CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A software vendor releases a security advisory stating that attackers are actively exploiting a flaw in their product for which no patch currently exists. Which term best describes this vulnerability?
- AEnd-of-life vulnerability
- BZero-day vulnerability
- CMisconfiguration vulnerability
- DLegacy vulnerability
Show answer & explanationAnswer & explanation
Correct answer: B. Zero-day vulnerability
A zero-day vulnerability is one that is being actively exploited or is publicly known before the vendor has released a patch, giving defenders zero days to respond before exposure begins.
Why the other options are wrong
- A. End-of-life refers to software no longer supported by the vendor, which is a different scenario.
- C. Misconfiguration refers to improper settings, not a fundamental unpatched software flaw.
- D. Legacy vulnerabilities relate to outdated but still supported systems, not necessarily unpatched flaws.
Zero-Day Vulnerability
A software flaw that is unknown to or unaddressed by the vendor, often exploited before a patch is available.
- No official patch exists at time of exploitation
- High risk due to lack of defenses
- Often sold/traded on underground markets before disclosure
Memory trick: Zero-day means zero days of warning before it's used against you.