Hacker News new | ask | show | jobs
by biddlesby 2133 days ago
Yeah, it’s really confusing. Unless I don’t understand the term, it hasn’t been a zero day vulnerability for the past two years...
1 comments

The days are counted from the release of a fix. If something been known for two years but a fix was released on 11th August, then it was a zero-day for the two years until 11th August and it's a "day-6" vulnerability today.

IIRC the term was introduced to contrast with day-1 attacks with exploits developed by reverse engineering patches on the day they are released and attempting to exploit systems in the gap until they get patched.

I see. Thank you for the explanation!