← Back to context

Comment by somat

23 days ago

Yes, but they can only be analyzed, patched and distributed "After" the attack is known.

A zero day attack is where there have been zero days since the attack mechanism is discovered(by the victim, not the attacker obviously), there is no after. There is no time for a fix to be developed. When you get hit one day after the attack vector is known that would be a one day attack. if you get a fix one day after the attack that would be a one day patch. If the vulnerability gets discovered and patched before the attack occurs, then there is no zero day attack. only multi day ones on people who did not get or apply the patch.