Microsoft starts removing WMIC tool used by cybercriminals

Microsoft has finally begun removing a long-abused tool from its latest Windows 11 builds, a move that’s expected to significantly boost the operating system’s security posture. The Windows Management Instrumentation Command-line (WMIC) tool, which has been a favorite among cybercriminals for its ability to interact with Windows systems using text commands, will no longer be available in Windows 11 versions 24H2 and 25H2.

For those unfamiliar with WMIC, it’s a built-in command-line utility that allows users to query and manage system settings, as well as perform tasks such as deleting Shadow Volume Copies – a technique commonly used by ransomware attackers. However, its flexibility and Microsoft-signed status made it an attractive tool for malicious actors, who have abused it in various ways, including querying for installed security solutions and uninstalling them.

The removal of WMIC is part of a broader effort by Microsoft to rid its operating systems of outdated and insecure tools. As early as 2016, the company deprecated WMIC in Windows Server 2012, and later converted it into a Feature on Demand (FoD) starting with Windows 11 version 22H2. This change will not only limit the capabilities of malicious actors but also reduce the attack surface for legitimate users.

The move is expected to have significant security benefits, as WMIC’s removal will prevent cybercriminals from using it to evade detection and carry out various forms of malware activity. For instance, ransomware attackers often rely on WMIC to delete Shadow Volume Copies, making it impossible for victims to recover their encrypted data. By removing this tool, Microsoft is effectively shutting down a key tactic used by these attackers.

While the removal only applies to the legacy WMIC component and not its underlying WMI system, IT administrators who have relied on WMIC will need to adjust their workflows accordingly. Fortunately, Microsoft has provided guidance for those who use WMIC, recommending that they switch to PowerShell or other modern tools such as WMI’s COM API, .NET libraries, or scripting languages.

In practical terms, this change means that users and organizations should expect a smoother and more secure Windows experience going forward. As the operating system continues to evolve, it’s essential for both individuals and businesses to stay informed about security updates and changes like these. By doing so, they can ensure their systems are protected against emerging threats and maintain the highest level of security possible.

In summary, Microsoft’s decision to remove WMIC from its latest Windows 11 builds marks an important step towards improving the operating system’s overall security posture. As users and organizations upgrade to newer versions, it’s crucial that they also adapt their workflows to take advantage of these changes and reduce their vulnerability to cyber threats.


Source: Bleeping Computer — 2026-08-18