EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewMedium

A security researcher discovers a flaw in a popular web browser that allows an attacker to execute arbitrary code on a user's machine simply by visiting a malicious website. The researcher responsibly discloses this vulnerability to the browser vendor, giving them time to develop and release a patch before publicly revealing the details. This type of vulnerability, unknown to the vendor and public, is commonly referred to as a:

  1. AZero-Day Exploit
  2. BBuffer Overflow
  3. CCross-Site Request Forgery (CSRF)
  4. DPhishing Vulnerability
Show answer & explanation

Correct answer: A. Zero-Day Exploit

A zero-day exploit refers to a vulnerability that is unknown to the software vendor and for which no patch or fix has been publicly released. The 'zero-day' refers to the fact that the vendor has had 'zero days' to fix it since its discovery by an attacker.

Why the other options are wrong

  • B. Buffer Overflow is a specific type of vulnerability, not a classification for its discovery status.
  • C. CSRF is a specific web application vulnerability, not a classification for the novelty of a flaw.
  • D. Phishing is an attack technique, not a vulnerability type in a browser.

Zero-Day Exploit

A cyberattack that exploits a software vulnerability previously unknown to the software vendor or the public. This means there is no patch or fix available for the vulnerability at the time of the attack.

  • Vulnerability is unknown to vendor and public.
  • No patch or fix exists at the time of discovery/attack.
  • Highly dangerous due to lack of immediate defense.
  • Often discovered by malicious actors or security researchers.

Memory trick: Zero-day means zero time to patch.

More Information Security and Ethical Hacking Overview questions