What is a zero-day vulnerability?
A zero-day is a software weakness that attackers can use before a fix exists. What that means for a business, and what protects you meanwhile.
A zero-day vulnerability is a weakness in software that attackers find and can use before the maker has released a fix. The United States standards body NIST defines a zero-day attack as one that exploits a previously unknown vulnerability in hardware, firmware or software.
How it differs from an ordinary vulnerability
With most vulnerabilities, the maker releases a patch and your job is to install it promptly. With a zero-day there is nothing to install yet. Every copy of the software is exposed, including the ones that are fully up to date.
Because of that, zero-days are worth money. The UK’s National Cyber Security Centre (NCSC) describes a market in newly discovered flaws, and says they are often used in tailored attacks by the more capable and better resourced attackers.
What happens once it is public
A zero-day does not stay secret. Once it is publicly known, the NCSC says, reusable attacks are developed and it quickly becomes a tool that ordinary criminals can use. From then on it is a risk to any system that has not had the patch applied.
The Australian Signals Directorate (ASD) gives a sense of the speed. Once a vulnerability in an online service is made public, attack code can be expected within 48 hours, sometimes within 24.
What you can do when there is no patch
ASD’s patching guidance says a temporary workaround may be the only effective protection while no patch is available. Makers often publish one with the announcement or soon after. A workaround is usually one of two things:
- switching off the part of the software that has the weakness
- restricting or blocking access to the affected service with a firewall or a similar control.
A workaround is temporary. ASD’s advice is to apply the real patch as a follow-up when it arrives. For systems that face the internet, its guidance allows 48 hours when the maker rates a vulnerability as critical or a working attack exists.
Why layers matter
While there is no patch, your other defences have to do the work. The NCSC’s advice is defence in depth: several layers, so that you have more than one chance to notice an intruder and limit the damage. For a small business, those layers are familiar ones.
- Multi-factor authentication, so a stolen password is not enough on its own.
- Standard accounts for daily work, with administrator rights kept to the few people who need them.
- Fewer services open to the internet.
- Backups kept apart from the network, as in the 3-2-1 backup rule.
Questions for whoever looks after your IT
- How do you hear about urgent security announcements for the products we use?
- Which of our systems can be reached from the internet?
- How quickly can you apply a workaround or an emergency patch, including out of hours?
The Essential Eight: where a small business should start explains the layers in more detail. Watching for urgent announcements and unusual activity is the work of our threat detection and monitoring service.
Sources
- Zero-day attack: glossary definition (NIST Computer Security Resource Center) csrc.nist.gov
- Understanding vulnerabilities (UK National Cyber Security Centre) ncsc.gov.uk
- Patching applications and operating systems (Australian Signals Directorate) cyber.gov.au
- Mitigating malware and ransomware attacks (UK National Cyber Security Centre) ncsc.gov.uk