this post was submitted on 10 Jul 2024
323 points (98.8% liked)

Technology

57435 readers
3274 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 33 points 1 month ago (1 children)

If it's a zero day then Microsoft didn't know about it. If Microsoft knew about the exploit for a year it was not a zero day.

[–] [email protected] 2 points 1 month ago (1 children)

Zero Day just means that you have zero days to fix it before it becomes a problem. Doesn't mean that you actually take zero days to fix it.

[–] [email protected] 11 points 1 month ago (2 children)

What? No it doesn't, it means that the exploit has been known for zero days, aka it's an unknown exploit.

[–] [email protected] 19 points 1 month ago

A zero-day (also known as a 0-day) is a vulnerability in software or hardware that is typically unknown to the vendor and for which no patch or other fix is available. The vendor has zero days to prepare a patch as the vulnerability has already been described or exploited.

From wiki

[–] [email protected] 7 points 1 month ago

My understanding, zero day means when the exploit was discovered it was already being used in the wild. This is different from an exploit discovered by a bounty program or by security researchers.