PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-0450 Google CVE debrief

CVE-2017-0450 is an Android elevation-of-privilege issue in Audioserver. According to the CVE description, a local malicious application could execute arbitrary code in the context of a privileged process. The issue is rated Moderate in the vendor description because it is mitigated by current platform configurations, but NVD assigns a High CVSS score (7.8).

Vendor
Google
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-08
Original CVE updated
2026-05-13
Advisory published
2017-02-08
Advisory updated
2026-05-13

Who should care

Android security teams, mobile device administrators, OEMs, and app-review or endpoint teams responsible for devices running affected Android versions, especially those at or below 7.1.1 per NVD.

Technical summary

The NVD record describes a local attack requiring user interaction that could let an unprivileged app execute code within a privileged Audioserver process. NVD’s affected CPE range includes Android versions through 7.1.1. The CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a local, user-interaction-dependent path with potentially broad impact if exploited.

Defensive priority

High

Recommended defensive actions

  • Review Android patch status for devices at or below the affected version range listed by NVD.
  • Prioritize remediation on devices that process untrusted apps or have delayed security updates.
  • Use the Android Security Bulletin reference to confirm whether the relevant patch level is present on managed devices.
  • Monitor for local privilege-escalation indicators on endpoints that are unable to update promptly.
  • Track vendor guidance and NVD updates for any changes to affected versions or severity context.

Evidence notes

Source corpus evidence is limited to the official CVE/NVD record and Android security bulletin reference. NVD states that a local malicious application could execute arbitrary code in a privileged process, and its CPE criteria list Android through 7.1.1 as vulnerable. The Android bulletin reference is included in the record as the vendor advisory/patch source. No KEV listing or ransomware association is present in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-0450 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-0450

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-0450 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0450

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.