Microsoft Office Ltsc 2024 vulnerabilities
319 known vulnerabilities affecting microsoft/microsoft_office_ltsc_2024.
Total CVEs
319
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
HIGH273MEDIUM38LOW8
Vulnerabilities
Page 13 of 16
CVE-2024-43505P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-10-08
CVE-2024-43505 [HIGH] CWE-357 CVE-2024-43505: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2024-49027P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49027 [HIGH] CWE-416 CVE-2024-49027: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2024-49028P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49028 [HIGH] CWE-125 CVE-2024-49028: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2024-49030P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49030 [HIGH] CWE-122 CVE-2024-49030: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2024-49029P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49029 [HIGH] CWE-908 CVE-2024-49029: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2025-21356P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-01-14
CVE-2025-21356 [HIGH] CWE-122 CVE-2025-21356: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2025-30375P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30375 [HIGH] CWE-843 CVE-2025-30375: Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-30383P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30383 [HIGH] CWE-843 CVE-2025-30383: Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40360P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2026-05-12
CVE-2026-40360 [HIGH] CWE-125 CVE-2026-40360: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-20949P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2026-01-13
CVE-2026-20949 [HIGH] CWE-284 CVE-2026-20949: Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a securi
Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2024-49032P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49032 [HIGH] CWE-416 CVE-2024-49032: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2024-49031P3HIGHCVSS 7.8≥ 1.0.0, < https://aka.ms/OfficeSecurityReleases2024-11-12
CVE-2024-49031 [HIGH] CWE-126 CVE-2024-49031: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2025-24083P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-03-11
CVE-2025-24083 [HIGH] CWE-822 CVE-2025-24083: Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-21345P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-01-14
CVE-2025-21345 [HIGH] CWE-416 CVE-2025-21345: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2025-30381P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30381 [HIGH] CWE-125 CVE-2025-30381: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-32705P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-32705 [HIGH] CWE-125 CVE-2025-32705: Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code local
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-29792P3HIGHCVSS 7.3≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-04-08
CVE-2025-29792 [HIGH] CWE-416 CVE-2025-29792: Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21346P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-01-14
CVE-2025-21346 [HIGH] CWE-693 CVE-2025-21346: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2025-30379P3HIGHCVSS 7.8≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-05-13
CVE-2025-30379 [HIGH] CWE-763 CVE-2025-30379: Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to
Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62555P3HIGHCVSS 7.0≥ 16.0.0, < https://aka.ms/OfficeSecurityReleases2025-12-09
CVE-2025-62555 [HIGH] CWE-416 CVE-2025-62555: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd