Attacks
Exploit
What is an exploit?
An exploit is the code that actually takes advantage of a weakness. The weakness is the flaw in the program. The exploit is the tool that turns it into access.
The distinction matters when judging risk. A known weakness for which no exploit is circulating is rarely attacked. As soon as a working exploit is publicly available the situation changes, because attackers without skills of their own can then work with it.
For that reason it is not enough to sort weaknesses by severity alone. A medium weakness that is being actively exploited is more urgent than a critical one for which no tool exists.
In practice that means systems reachable from the internet need their updates first. That is where the path between a published exploit and your business is shortest.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.