Office Long Term Servicing Channel
Vendor:
First CVE: Oct 13, 2021 · Active for 4 years
368
Total CVEs
More Total CVEs than 100% of tracked products
61.3
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 63% of tracked products
2.4%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Office Long Term Servicing Channel over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 2021
4 years ago
Most Recent CVE
May 12, 2026
77 days ago
CVE Severity & Scoring
Office Long Term Servicing Channel368 CVEs
13%
85%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local327 (88.9%)
Network41 (11.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low353 (95.9%)
High15 (4.1%)
Unknown0 (0.0%)
User Interaction
None71 (19.3%)
Unknown0 (0.0%)
Required297 (80.7%)
Privileges Required
Low37 (10.1%)
High0 (0.0%)
None331 (89.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (368 CVEs).
368 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21413CRITICAL Microsoft Outlook Remote Code Execution Vulnerability | Feb 13, 2024 | 9.8 | 96 | YES | NO |
CVE-2023-23397CRITICAL Microsoft Outlook Elevation of Privilege Vulnerability | Mar 14, 2023 | 9.8 | 96 | YES | NO |
CVE-2026-21509HIGH Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | Jan 26, 2026 | 7.8 | 94 | YES | NO |
CVE-2021-42292HIGH Microsoft Excel Security Feature Bypass Vulnerability | Nov 10, 2021 | 7.8 | 79 | YES | NO |
CVE-2023-21716CRITICAL Microsoft Word Remote Code Execution Vulnerability | Feb 14, 2023 | 9.8 | 77 | NO | NO |
CVE-2023-35311HIGH Microsoft Outlook Security Feature Bypass Vulnerability | Jul 11, 2023 | 8.8 | 73 | YES | NO |
CVE-2024-38189HIGH Microsoft Project Remote Code Execution Vulnerability | Aug 13, 2024 | 8.8 | 71 | YES | NO |
CVE-2026-21514HIGH Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | Feb 10, 2026 | 7.8 | 70 | YES | NO |
CVE-2023-36761MEDIUM Microsoft Word Information Disclosure Vulnerability | Sep 12, 2023 | 6.5 | 70 | YES | NO |
CVE-2024-38226HIGH Microsoft Publisher Security Feature Bypass Vulnerability | Sep 10, 2024 | 7.3 | 65 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (368 CVEs).
CISA KEV
9 CVEs
2.4% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
3.0% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (368 CVEs).
Media Mentions
Signals from CVEs in this product scope (368 CVEs).
Top CNAs Publishing CVEs For Office Long Term Servicing Channel
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2024 | 219 | 7.7 | 0.9% | 2 | 5 |
| 2021 | 357 | 7.6 | 2.4% | 9 | 11 |