EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewMedium
A security researcher discovers a flaw in a popular web browser that allows an attacker to execute arbitrary code on a user's machine simply by visiting a malicious website. The researcher responsibly discloses this vulnerability to the browser vendor, giving them time to develop and release a patch before publicly revealing the details. This type of vulnerability, unknown to the vendor and public, is commonly referred to as a:
- AZero-Day Exploit
- BBuffer Overflow
- CCross-Site Request Forgery (CSRF)
- DPhishing Vulnerability
Show answer & explanationAnswer & explanation
Correct answer: A. Zero-Day Exploit
A zero-day exploit refers to a vulnerability that is unknown to the software vendor and for which no patch or fix has been publicly released. The 'zero-day' refers to the fact that the vendor has had 'zero days' to fix it since its discovery by an attacker.
Why the other options are wrong
- B. Buffer Overflow is a specific type of vulnerability, not a classification for its discovery status.
- C. CSRF is a specific web application vulnerability, not a classification for the novelty of a flaw.
- D. Phishing is an attack technique, not a vulnerability type in a browser.
Zero-Day Exploit
A cyberattack that exploits a software vulnerability previously unknown to the software vendor or the public. This means there is no patch or fix available for the vulnerability at the time of the attack.
- Vulnerability is unknown to vendor and public.
- No patch or fix exists at the time of discovery/attack.
- Highly dangerous due to lack of immediate defense.
- Often discovered by malicious actors or security researchers.
Memory trick: Zero-day means zero time to patch.