Feb 26, 2019 · Example: QID - 371535 (PuTTY SCP Client Spoofing Vulnerability). This impacts all released versions of putty (.7 and under). No patch has been released. However, Qualys doesn't call this a zero-day. The standard definition of a 0-day most companies use is a vulnerability that has been released/published/announced that has no patch.

The Zero Day Initiative (ZDI) was created to encourage the reporting of 0-day vulnerabilities privately to the affected vendors by financially rewarding researchers. At the time, there was a perception by some in the information security industry that those who find vulnerabilities are malicious hackers looking to do harm. What is a zero-day exploit or attack? When hackers or threat actors successfully develop and deploy proofs of concept (PoCs) or an actual malware that exploits the vulnerability while the vendor is still working on rolling out a patch (or sometimes, unaware of the vulnerability’s existence), it becomes a zero-day exploit or attack.

