Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security
Software Vulnerabilities and Threats: Malware, SQL Injection, Zero-Day
Updated 11 October 2026 · Fact-checked
A **software vulnerability** is a weakness in code, design or configuration that an attacker can exploit. A **threat** is the actor or event that exploits it. To answer exam questions, define the term, explain how the attack works, state the impact, and give controls. Common examples are malware, bugs, buffer overflow, SQL injection and zero-day exploits.
Understand Software Vulnerabilities and Threats
Software is written by people, so it contains mistakes. Some mistakes only cause wrong output. Others open a door for an attacker. A vulnerability is such a door: a flaw in code, design, configuration or a third-party component. A threat is anything that can use that door, such as a hacker, a malware program or an insider. Risk is the chance that a threat uses a vulnerability, multiplied by the damage it would cause. An exploit is the actual code or technique used to take advantage of the flaw.
A bug is a coding or logic error. Most bugs are harmless, but a bug that lets someone bypass a check or read memory they should not is a security vulnerability. A buffer overflow happens when a program writes more data into a fixed-size memory area (buffer) than it can hold. The extra data spills into nearby memory. An attacker can use this to crash the program or to run their own code. It is common in languages that do not check memory bounds automatically. The fix is input length checking, safe functions and memory-safe languages.
SQL injection happens when an application builds a database query by joining user input directly into the query text. An attacker types SQL commands into a form field, and the database runs them. For example, entering ' OR '1'='1 in a password box can make a login condition always true. The attacker may read, change or delete data. The main defences are parameterised queries (prepared statements), input validation, least-privilege database accounts and hiding detailed error messages.
A zero-day vulnerability is a flaw unknown to the vendor, so no patch exists yet. A zero-day exploit uses it, and the vendor has had "zero days" to fix it. Defence relies on layered controls: monitoring, network segmentation, least privilege and quick patching once a fix is released.
Malware is malicious software. A virus attaches to a file or program and spreads when the host is run, usually needing user action. A worm spreads by itself across networks without needing a host file. A trojan pretends to be useful software but carries a hidden payload and does not self-replicate. Ransomware encrypts data and demands payment. Spyware secretly collects information. A rootkit hides malicious activity, and a botnet is a group of infected machines controlled remotely.
Key rules to remember
- Risk relationship
- Risk = Threat × Vulnerability × Impact
- A conceptual relationship, not a numeric calculation. If any one is absent, risk is low.
- Vulnerability vs threat vs exploit
- Vulnerability = weakness; Threat = possible danger; Exploit = method that uses the weakness
- Define all three separately. Examiners often test the difference.
- Malware spread rule
- Virus needs a host and user action; Worm self-spreads; Trojan disguises and does not self-replicate
- Use this one-line contrast in any 'differentiate' question.
- SQL injection defence
- Parameterised query + input validation + least privilege
- Parameterised queries are the primary defence; the others support it.
- Zero-day
- Unknown to vendor + no patch + exploited = zero-day attack
- Once the vendor issues a patch, it is no longer a zero-day, though unpatched systems stay exposed.
How to solve Software Vulnerabilities and Threats questions
Use this structure for any theory or case question on software vulnerabilities and threats.
- 1Identify what is asked: define, differentiate, explain how it works, or advise on a case.
- 2Define the key term in one or two precise lines, separating vulnerability, threat and exploit where relevant.
- 3Explain the mechanism step by step: what the flaw is, how the attacker uses it, what happens.
- 4State the impact on confidentiality, integrity and availability of data or systems.
- 5List preventive and detective controls: patching, secure coding, validation, least privilege, antivirus, monitoring.
- 6For case questions, apply the facts: name the likely attack, the weakness shown, and the immediate response.
- 7Link to law where the question invites it, such as the IT Act, 2000 offences and the duty to keep reasonable security practices, in plain words without unsure section numbers.
- 8Close with a one-line conclusion or recommendation.
Quickest way: Define, Mechanism, Impact, Control
When to use it: Use when time is short or the question is worth few marks.
- Write a one-line definition.
- Add one line on how the attack works, with a small example.
- Add one line on impact (data loss, downtime, fraud).
- Add two or three controls.
- For differentiate questions, give three to four contrast points in a list.
Common mistakes in Software Vulnerabilities and Threats
Using virus, worm and trojan as if they mean the same thing.
People use 'virus' for all malware in daily speech.
Fix: Anchor on spread: virus needs a host file, worm spreads alone, trojan disguises itself and does not self-replicate.
Saying a zero-day is a brand-new virus.
The word 'new' sounds right.
Fix: A zero-day is a flaw unknown to the vendor with no patch available. It is about the vulnerability, not the type of malware.
Describing SQL injection as hacking the network or server directly.
Students mix it with general hacking.
Fix: State that it works through unvalidated user input placed into a database query by the application.
Giving only the attack and no controls.
Students stop once the mechanism is explained.
Fix: Always add prevention and response points. Many marks sit there.
Confusing a vulnerability with a threat.
Both appear in the same sentences.
Fix: Vulnerability is the weakness inside the system. Threat is the outside actor or event that can use it.
Claiming patching removes all zero-day risk.
Overstating a good control.
Fix: Patching helps only after a fix exists. Before that, use layered defences and monitoring.
Worked examples
Example 1
A Mumbai-based online retailer's login page lets a user enter ' OR '1'='1 and gain access without a password. Identify the attack, explain how it works and advise the company.
Show the solution
- Attack: this is SQL injection, caused by the application placing user input directly into a database query.
- Mechanism: the query checks username and password. The injected text makes the condition ' OR '1'='1 always true, so the check passes.
- Weakness shown: no input validation and no parameterised queries.
- Impact: an attacker may read customer records, alter orders or delete data. This hits confidentiality and integrity and may cause legal exposure for failing to protect personal data.
- Advice: switch to parameterised queries, validate input, give the database account least privilege, hide detailed error messages, test the code and review logs for past misuse.
Answer: The attack is SQL injection. The company should use parameterised queries, input validation and least-privilege database accounts, then review logs and test the application.
Example 2
Differentiate between a virus, a worm and a trojan, and explain why a zero-day vulnerability is dangerous.
Show the solution
- Virus: attaches itself to a host file or program, activates when the host runs, usually needs user action to spread.
- Worm: standalone program that copies itself across networks without a host file or user action, and can consume bandwidth quickly.
- Trojan: appears as useful software but hides a malicious payload. It does not self-replicate and relies on the user installing it.
- Zero-day: a flaw unknown to the vendor, so no patch exists.
- Danger: signature-based tools may not detect the exploit and users cannot patch, so attackers have a window of free use.
- Mitigation: network segmentation, least privilege, behaviour-based monitoring, backups and fast patching once a fix is released.
Answer: A virus needs a host and user action, a worm spreads by itself, and a trojan disguises itself without self-replicating. A zero-day is dangerous because no patch exists, leaving systems exposed until the vendor fixes it.
Exam tips
- Keep a standard four-part answer: definition, mechanism, impact, controls.
- For differentiate questions, use short bullet points with the spreading method as the main contrast.
- Use a small example for SQL injection and buffer overflow. It shows understanding and earns marks.
- In case questions, name the attack first, then link each fact in the scenario to the weakness.
- Mention relevant IT Act, 2000 duties in plain words only when the question gives a legal angle, and do not quote section numbers you are unsure of.
Practice questions from Softwares and Software Security
- Arjun's firm is developing an e-filing portal. The client is unsure about the final screens and expects frequent changes after seeing early …
- Which activity is characteristic of a secure SDLC, as distinct from an ordinary SDLC?
- A company secretary is told that a software team has finished writing code for a payroll module and now plans to run unit, integration and s…
- Meera Systems Pvt. Ltd. engages an independent freelancer to write custom software. The contract is silent on ownership. As per the general …
- Under the Indian Copyright Act, 1957, a computer programme is protected as which type of work?
Software Vulnerabilities and Threats: frequently asked questions
What is a zero-day vulnerability?
It is a software flaw unknown to the vendor, so no patch is available. Attackers who find it can exploit it before a fix exists. That is why it is called zero-day.
How does SQL injection work?
An application joins user input into a database query without checking it. The attacker types SQL code into an input field, and the database runs it. This can expose or change data. Parameterised queries are the main defence.
What is the difference between a virus, a worm and a trojan?
A virus attaches to a host file and needs user action to spread. A worm spreads on its own across networks. A trojan pretends to be useful software and does not copy itself.
What is a buffer overflow?
It occurs when a program writes more data into a memory area than it can hold. The extra data overwrites nearby memory, which can crash the program or let an attacker run code. Bounds checking and safe coding prevent it.