End of Support is not always the end of security updates. We had some for XP years ago, or this month for Exchange 2010. It seems to depend on CVE score and severity.
As working for a MS Gold Partner I can share more details:
For Extended Support as Joe_Lurie you guessed a (quite expensive) support contract.
It is also only break and fix, so you need to provide evidence it was caused by an security update - as there are no other changes in LTSC or previous Windows Server.
Plus there is no guarantuee they will provide a private fix of issues as long they are not security related.
There is a MS doc describing the mainstream and extended support differences but don't have it at hand but read it about 3 months ago.
The said Premium Assurance is not needed for public security fixes you will still receive until EOS of Server 2012 and Server 2012 R2.
for all public