Microsoft has removed the legacy WMIC command-line tool from new Windows 11 installations, taking away a built-in utility that cybercriminals have repeatedly abused during attacks.

The change affects Windows 11 versions 24H2 and 25H2, along with this week’s Windows 11 beta releases. While WMIC is disappearing, the underlying Windows Management Instrumentation platform remains available.

Microsoft removes WMIC from Windows 11

WMIC, short for Windows Management Instrumentation Command-line, lets users run text-based commands to query and manage Windows systems.

Microsoft began phasing out the tool years ago. It deprecated WMIC in Windows Server 2012 and Windows 10 version 21H1, then made it an optional Feature on Demand in Windows 11 22H2.

Now, Microsoft removes WMIC completely from fresh installations of Windows 11 24H2 and 25H2. Users can no longer add it through the optional Features on Demand menu.

The company also confirmed that its latest Windows 11 beta builds no longer include the command-line tool.

WMI itself remains available

The removal only affects the old WMIC utility. Windows Management Instrumentation, commonly known as WMI, will continue to work as normal.

WMI allows administrators and software to collect system information, monitor devices and automate management tasks. IT teams that still rely on WMIC can instead use PowerShell, WMI’s COM API, .NET libraries or supported scripting languages.

Microsoft recommends that administrators update old scripts and workflows before WMIC disappears from more Windows environments.

Malware operators often abuse WMIC

Microsoft removes WMIC partly because attackers have long treated it as a living-off-the-land binary, or LOLBIN. These are legitimate, Microsoft-signed tools that criminals can exploit without first installing their own software.

Ransomware groups have frequently used WMIC commands to delete Shadow Volume Copies. This tactic prevents victims from restoring encrypted files through Windows backup snapshots.

Attackers have also used the tool to identify installed antivirus products and security software. In some cases, malware operators then attempted to disable or remove those protections before launching further payloads.

Other attacks have used WMIC to add exclusions to Microsoft Defender. Those exclusions can allow malicious files or folders to avoid security scans on compromised devices.

Removal closes off a common attack path

Removing WMIC will not stop every Windows attack. Threat actors can still use PowerShell, WMI and other legitimate tools if they gain access to a device.

However, the move removes one familiar option from an attacker’s toolkit. It also reduces the number of outdated Windows components that organisations must monitor and secure.

For most users, the change should have little effect. Administrators and legacy software users may need to replace WMIC commands with supported alternatives before deploying newer Windows 11 versions.


0 responses to “Microsoft Removes WMIC From New Windows 11 Builds”