Cyber

Microsoft starts removing WMIC tool used by cybercriminals

Microsoft has officially begun removing the legacy WMIC command-line tool starting with Windows 11 version 24H2 and recent beta builds.

·1 min read
Microsoft starts removing WMIC tool used by cybercriminals

In a significant security move, Microsoft announced that it has removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from the latest Windows 11 beta builds released this week.

While the legacy administration utility was historically useful for system management, it has increasingly been leveraged by cybercriminals and threat actors to conduct system reconnaissance and execute malicious payloads.

Removing WMIC helps mitigate certain classes of attacks by eliminating a frequently abused component, thereby forcing attackers to find alternative, potentially noisier methods for executing system queries.

For IT administrators and security professionals, this removal requires attention to legacy scripts and automation workflows that might still rely on WMIC commands for inventory or management tasks.

Experts recommend auditing existing infrastructures and transitioning to modern, secure alternatives like PowerShell to ensure compatibility and maintain strong security postures on updated operating systems.

#Microsoft#Windows 11#WMIC#Kiberxavfsizlik#BleepingComputer

Related articles