The US Cyber Command has issued an unprecedented warning saying it has discovered “active malicious use” of a Microsoft Outlook vulnerability by Iran.
The vulnerability concerns a security flaw in Outlook that Microsoft patched in 2017, but several unpatched computers are still at risk.

The US Cyber Command tweet states:
“ USCYBERCOM has discovered active malicious use of “CVE-2017-11774” and recommends immediate #patching.”
The “CVE-2017-11774” first discovered by SensePost researchers was created by an Iranian hacking group known as APT33 (or Elfin), known for developing the Shamon malware – another hacking tool.
The Outlook bug allows a hacker to escape the sandbox Outlook and execute malicious code on the operating system.

" In December 2018, ATP 33 hackers used the vulnerability to deploy backdoors on web servers , which were later used to push the CVE -2017-11774 exploit to users' inboxes to infect their systems with malware ," the report states.
Security firm FireEye has also extensively reported on APT 33's connectionto Iran.
“In recent years, we have been monitoring a distinct, lesser-known Iranian group with potentially destructive capabilities, which we call APT33,” FireEye said recently.
The analysis reveals that APT33 is a capable group that has carried out cyber espionage since at least 2013 at the behest of the Iranian government.

APT33 has targeted organizations – spanning multiple industries – based in the US, Saudi Arabia, and South Korea.
The possible attack by Iran is likely to come in response to the country's rather tense relations with the US.
America, for its part, appears to be concerned about a future cyberattack by the Iranians, as several cybersecurity firms said they had already seen signs that Tehran was targeting relevant computer networks for intrusion, and appeared particularly focused on the US government and the energy sector, including oil and gas suppliers.
