Exploit

Code or technique that takes advantage of a specific vulnerability to achieve an attacker goal.

An exploit is the concrete code or technique that turns a vulnerability into an actual compromise — the weaponization step. The risk equation is threat actor + vulnerability + exploit = active attack; remove any one and there’s no incident. Public exploit availability (proof-of-concept code, Metasploit modules) sharply raises urgency, feeding the CVSS Temporal metric group (renamed the “Threat” group in CVSS 4.0) and threat-intel feeds like CISA KEV that flag what’s being exploited in the wild.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Threats, Vulnerabilities, and Mitigations