cbcvebase.

Microsoft Office Ltsc 2024 vulnerabilities

319 known vulnerabilities affecting microsoft/microsoft_office_ltsc_2024.

Total CVEs
319
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
HIGH273MEDIUM38LOW8

Vulnerabilities

Page 13 of 16
CVE-2024-43505P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-10-08
CVE-2024-43505 [HIGH] CWE-357 CVE-2024-43505: Microsoft Office Visio Remote Code Execution Vulnerability Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2024-49027P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49027 [HIGH] CWE-416 CVE-2024-49027: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2024-49028P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49028 [HIGH] CWE-125 CVE-2024-49028: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2024-49030P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49030 [HIGH] CWE-122 CVE-2024-49030: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2024-49029P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49029 [HIGH] CWE-908 CVE-2024-49029: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2025-21356P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-01-14
CVE-2025-21356 [HIGH] CWE-122 CVE-2025-21356: Microsoft Office Visio Remote Code Execution Vulnerability Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2025-30375P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30375 [HIGH] CWE-843 CVE-2025-30375: Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-30383P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30383 [HIGH] CWE-843 CVE-2025-30383: Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40360P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2026-05-12
CVE-2026-40360 [HIGH] CWE-125 CVE-2026-40360: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-20949P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2026-01-13
CVE-2026-20949 [HIGH] CWE-284 CVE-2026-20949: Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a securi Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2024-49032P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49032 [HIGH] CWE-416 CVE-2024-49032: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2024-49031P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49031 [HIGH] CWE-126 CVE-2024-49031: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2025-24083P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-03-11
CVE-2025-24083 [HIGH] CWE-822 CVE-2025-24083: Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-21345P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-01-14
CVE-2025-21345 [HIGH] CWE-416 CVE-2025-21345: Microsoft Office Visio Remote Code Execution Vulnerability Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2025-30381P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30381 [HIGH] CWE-125 CVE-2025-30381: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-32705P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-32705 [HIGH] CWE-125 CVE-2025-32705: Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code local Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-29792P3HIGHCVSS 7.3≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-04-08
CVE-2025-29792 [HIGH] CWE-416 CVE-2025-29792: Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21346P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-01-14
CVE-2025-21346 [HIGH] CWE-693 CVE-2025-21346: Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2025-30379P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30379 [HIGH] CWE-763 CVE-2025-30379: Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62555P3HIGHCVSS 7.0≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-12-09
CVE-2025-62555 [HIGH] CWE-416 CVE-2025-62555: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
Microsoft Office Ltsc 2024 vulnerabilities | cvebase