An exploit is a piece of code, data, or sequence of actions that takes advantage of a vulnerability to cause unintended behaviour, such as gaining unauthorised access, escalating privileges, or executing arbitrary code. Exploits turn a latent weakness into a concrete attack and are studied both offensively, in penetration testing, and defensively, to prioritise remediation. A zero-day exploit targets a vulnerability for which no patch yet exists.

Overview

  • An exploit converts a latent vulnerability into a working attack.
  • It may deliver a payload that grants access, escalates privileges, or runs code.
  • Zero-day exploits target unpatched, often unknown, vulnerabilities.
  • Understanding exploits drives prioritisation of patching and defensive controls.

Mechanisms

  • Trigger: input or action that activates the vulnerable code path.
  • Payload: the code or effect delivered once control is gained.
  • Delivery: the attack vector carrying the exploit to the target.
  • Chaining: combining exploits to bypass mitigations or escalate.
  • Lifecycle: from proof-of-concept through weaponisation to remediation.

Applications

  • Demonstrating impact during authorised penetration testing.
  • Prioritising vulnerabilities with known weaponised exploits.
  • Driving threat intelligence on active exploitation.
  • Informing defensive hardening and patch urgency.

Provenance