PatchSiren cyber security CVE debrief
CVE-2017-0450 Google CVE debrief
CVE-2017-0450 is an Android elevation-of-privilege issue in Audioserver. According to the CVE description, a local malicious application could execute arbitrary code in the context of a privileged process. The issue is rated Moderate in the vendor description because it is mitigated by current platform configurations, but NVD assigns a High CVSS score (7.8).
- Vendor
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-08
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-08
- Advisory updated
- 2026-05-13
Who should care
Android security teams, mobile device administrators, OEMs, and app-review or endpoint teams responsible for devices running affected Android versions, especially those at or below 7.1.1 per NVD.
Technical summary
The NVD record describes a local attack requiring user interaction that could let an unprivileged app execute code within a privileged Audioserver process. NVD’s affected CPE range includes Android versions through 7.1.1. The CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a local, user-interaction-dependent path with potentially broad impact if exploited.
Defensive priority
High
Recommended defensive actions
- Review Android patch status for devices at or below the affected version range listed by NVD.
- Prioritize remediation on devices that process untrusted apps or have delayed security updates.
- Use the Android Security Bulletin reference to confirm whether the relevant patch level is present on managed devices.
- Monitor for local privilege-escalation indicators on endpoints that are unable to update promptly.
- Track vendor guidance and NVD updates for any changes to affected versions or severity context.
Evidence notes
Source corpus evidence is limited to the official CVE/NVD record and Android security bulletin reference. NVD states that a local malicious application could execute arbitrary code in a privileged process, and its CPE criteria list Android through 7.1.1 as vulnerable. The Android bulletin reference is included in the record as the vendor advisory/patch source. No KEV listing or ransomware association is present in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-0450 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-0450
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-0450 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0450
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://source.android.com/security/bulletin/2017-02-01.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.