PatchSiren cyber security CVE debrief
CVE-2017-0450 Google CVE debrief
CVE-2017-0450 is an Android elevation-of-privilege issue in Audioserver. According to the CVE description, a local malicious application could execute arbitrary code in the context of a privileged process. The issue is rated Moderate in the vendor description because it is mitigated by current platform configurations, but NVD assigns a High CVSS score (7.8).
- Vendor
- Product
- CVE-2017-0450
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-08
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-08
- Advisory updated
- 2026-05-13
Who should care
Android security teams, mobile device administrators, OEMs, and app-review or endpoint teams responsible for devices running affected Android versions, especially those at or below 7.1.1 per NVD.
Technical summary
The NVD record describes a local attack requiring user interaction that could let an unprivileged app execute code within a privileged Audioserver process. NVD’s affected CPE range includes Android versions through 7.1.1. The CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a local, user-interaction-dependent path with potentially broad impact if exploited.
Defensive priority
High
Recommended defensive actions
- Review Android patch status for devices at or below the affected version range listed by NVD.
- Prioritize remediation on devices that process untrusted apps or have delayed security updates.
- Use the Android Security Bulletin reference to confirm whether the relevant patch level is present on managed devices.
- Monitor for local privilege-escalation indicators on endpoints that are unable to update promptly.
- Track vendor guidance and NVD updates for any changes to affected versions or severity context.
Evidence notes
Source corpus evidence is limited to the official CVE/NVD record and Android security bulletin reference. NVD states that a local malicious application could execute arbitrary code in a privileged process, and its CPE criteria list Android through 7.1.1 as vulnerable. The Android bulletin reference is included in the record as the vendor advisory/patch source. No KEV listing or ransomware association is present in the supplied data.
Official resources
-
CVE-2017-0450 CVE record
CVE.org
-
CVE-2017-0450 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
- Source reference
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
CVE published on 2017-02-08. The supplied record includes an Android security bulletin reference dated 2017-02-01, but that bulletin date should not be treated as the CVE publication date. No KEV entry is listed in the supplied timeline.