Back to glossaryCyber

Zero-day vulnerability

A vulnerability unknown to the software vendor, for which no patch yet exists, and which can therefore be exploited before any defense is available.

Definition

A zero-day vulnerability is a flaw still unknown to the vendor of the software concerned, and for which, consequently, no patch has been released. The name conveys the idea that the victim has zero days to prepare, since the attack can occur before the flaw is even known. These vulnerabilities are the most dangerous, because they defeat defenses based on knowledge of existing threats, and the most sought after, being the object of a genuine market where they trade at high prices, whether among security researchers, states or malicious actors. For cyber insurance, the zero-day poses a particular challenge, because it escapes by construction the classic prevention measures, notably patch management, which is nonetheless one of the pillars of underwriting requirements. More seriously still, a zero-day affecting a very widespread product can strike a large number of insureds at once, turning a technical defect into an accumulation event. This is why underwriters care as much about an organization's speed of reaction, its ability to detect and contain an unknown exploitation, as about the mere updating of its systems.

Example

The MOVEit vulnerability, exploited en masse in 2023 by the Clop group before a patch was widely deployed, affected hundreds of organizations worldwide, illustrating how a single zero-day flaw can generate a wave of correlated losses.

Related terms
Related articles
Also known as

zero-day, 0-day, vulnérabilité jour zéro, faille jour zéro