PatchSiren cyber security CVE debrief
CVE-2017-0411 Google CVE debrief
CVE-2017-0411 is a high-severity Android elevation-of-privilege issue in Framework APIs. A local malicious app could use the flaw to execute arbitrary code in the context of a privileged process, increasing impact beyond normal third-party app permissions. The CVE was publicly published on 2017-02-08, and NVD ties it to Android 7.0, 7.1.0, and 7.1.1 with a CVSS 3.0 score of 7.8.
- Vendor
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-08
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-08
- Advisory updated
- 2026-05-13
Who should care
Android device owners and fleet administrators, OEM and MDM teams, and security teams managing devices that can install untrusted or sideloaded apps.
Technical summary
The issue is an elevation of privilege path in Android Framework APIs. NVD maps it to CWE-367 and rates it CVSS 3.0 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating local access plus user interaction are needed, but successful exploitation can lead to code execution inside a privileged process.
Defensive priority
High. This is not a remote wormable issue, but it crosses a privileged trust boundary on affected Android builds and can materially increase an attacker's capabilities on a device. Prioritize patching devices that still run the affected Android 7.x releases.
Recommended defensive actions
- Apply the Android security update referenced by the vendor bulletin and verify the device build includes the relevant fix level.
- Inventory Android devices to identify affected 7.x builds, including the versions listed by NVD.
- Restrict sideloading and untrusted app installation where policy allows, and enforce app distribution controls through MDM or platform settings.
- Review installed third-party apps on affected devices and remove anything suspicious or unnecessary until patching is complete.
- Use normal mobile security monitoring to watch for unexpected privileged-process behavior or unexplained app crashes on affected devices.
Evidence notes
The supplied CVE record was published on 2017-02-08 and last modified on 2026-05-13. NVD references the Android security bulletin at https://source.android.com/security/bulletin/2017-02-01.html and lists affected Android CPEs for 7.0, 7.1.0, and 7.1.1. The corpus also includes third-party references (SecurityFocus BID 96056, SecurityTracker 1037798) and an Exploit-DB entry; no exploit details are included here.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-0411 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-0411
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-0411 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0411
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://source.android.com/security/bulletin/2017-02-01.html
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/41354/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.