Microsoft Office 2024
Microsoft Office 2024
Third-party maintenance for the Microsoft Office 2024 costs 40-70% less than the OEM support contract, with 24/7 engineering support and same-day replacement parts.
Specifications
- product
- office
- release
- 2024
- product Label
- Microsoft Office
- release Label
- 2024
- codename
- lts
- latest Version
- release Date
- 2024-10-01
- maintained
- true
- source Url
- https://endoflife.date/office
Lifecycle Dates
- End of Service Life
- Oct 9, 2029
- Last OEM Support
- Oct 9, 2029
OEM vs. 3rd Party Support
See how 3rd party maintenance compares to traditional OEM support for your Microsoft Office 2024. Get the same level of service at a fraction of the cost.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| 24/7/365 Support | ||
| Same-Day Parts Replacement | Limited | |
| Mixed-Vendor Support | ||
| Flexible Contract Terms | Annual Only | Month-to-Month Available |
| Asset Lifecycle Extension | ||
| OEM-Trained Engineers |
Why Choose 3rd Party Support for Microsoft Office 2024?
Save 40-70%
Dramatically reduce your maintenance costs while maintaining the same level of support coverage.
Extend Asset Life
Continue using your Microsoft Office 2024 well beyond the OEM end-of-life date.
24/7 Expert Support
OEM-trained engineers available around the clock with same-day parts replacement.
Microsoft Office 2024 Support: Frequently Asked Questions
Is the Microsoft Office 2024 still supported?
Yes. The Microsoft Office 2024 is currently supported, and third-party maintenance is available as an alternative to the OEM contract at 40-70% lower cost.
When is the Microsoft Office 2024 end of service life (EOSL) date?
Microsoft lists the end of service life for the Microsoft Office 2024 as Oct 9, 2029.
Can I keep using the Microsoft Office 2024 after its EOSL date?
Yes. EOSL means Microsoft stops selling support contracts and issuing updates β the equipment itself keeps working. Third-party maintenance provides engineering support and replacement parts for as long as you choose to run it.
How much does third-party support for the Microsoft Office 2024 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location β request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Microsoft Office 2024
21 published CVEs affect the Microsoft Office 2024, including 18 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2007-0065 | HIGH | 10.0 | Feb 12, 2008 | Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request. |
| CVE-2009-2496 | HIGH | 9.3 | Aug 12, 2009 | Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption |
| CVE-2009-1534 | HIGH | 9.3 | Aug 12, 2009 | Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability." |
| CVE-2009-0562 | HIGH | 9.3 | Aug 12, 2009 | The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office We |
| CVE-2006-1311 | HIGH | 9.3 | Feb 13, 2007 | The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption. |
| CVE-2006-4694 | HIGH | 9.3 | Sep 27, 2006 | Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Win32/Controlppt.X, and Exploit-PPT.d/Trojan.PPDropper.F. NOTE: it has been reported that the attack vector involves SlideShowWindows.View.GotoNamedShow. |
| CVE-2006-1540 | HIGH | 9.3 | Mar 30, 2006 | MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an |
| CVE-2026-42831 | HIGH | 7.8 | May 12, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-21402 | HIGH | 7.8 | Jan 14, 2025 | Microsoft Office OneNote Remote Code Execution Vulnerability |
| CVE-2025-21361 | HIGH | 7.8 | Jan 14, 2025 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2025-21338 | HIGH | 7.8 | Jan 14, 2025 | GDI+ Remote Code Execution Vulnerability |
| CVE-2024-38250 | HIGH | 7.8 | Sep 10, 2024 | Windows Graphics Component Elevation of Privilege Vulnerability |
| CVE-2023-33158 | HIGH | 7.8 | Jul 11, 2023 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2023-24910 | HIGH | 7.8 | Mar 14, 2023 | Windows Graphics Component Elevation of Privilege Vulnerability |
| CVE-2007-3282 | HIGH | 7.8 | Jun 19, 2007 | Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method. |
| CVE-2026-42832 | HIGH | 7.7 | May 12, 2026 | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
| CVE-2005-2127 | HIGH | 7.5 | Aug 19, 2005 | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (a |
| CVE-2004-0848 | HIGH | 7.5 | Feb 8, 2005 | Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames. |
| CVE-2002-0862 | MEDIUM | 6.8 | Oct 4, 2002 | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for In |
| CVE-2007-3109 | MEDIUM | 6.4 | Jun 7, 2007 | The CERN Image Map Dispatcher (htimage.exe) in Microsoft FrontPage allows remote attackers to determine the existence, and possibly partial contents, of arbitrary files under the web root via a relative pathname in the PATH_INFO. |
Showing the 20 most severe of 21 known CVEs.
Get Third Party Support