Microsoft has removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from new Windows 11 beta builds released this week.

WMIC is a legacy command-line utility that allowed users and administrators to interact with Windows Management Instrumentation (WMI) through text-based commands. While WMI itself remains part of Windows, Microsoft is now completing the long-planned removal of the older WMIC interface.

The company first announced the move in September, saying that WMIC would be removed following upgrades to Windows 11 25H2 and later versions. Microsoft had already deprecated WMIC in Windows Server 2012 in 2016 and Windows 10 21H1 in 2021. Starting with Windows 11 22H2 in 2022, WMIC was converted into an optional Feature on Demand.

Microsoft announced in January 2024 that it would eventually remove the tool completely after first disabling it by default.

“Windows Management Instrumentation Command-line (WMIC) has been removed in this release,” Microsoft said in its release notes, explaining that the change is part of its ongoing effort to deprecate and remove WMIC from Windows.

Microsoft also confirmed that WMIC is already removed by default from new installations of Windows 11 24H2 and 25H2 and is no longer available as a Feature on Demand.

The removal affects only the legacy WMIC command-line component. Windows Management Instrumentation itself has not been removed and continues to work normally. Microsoft recommends that administrators replace WMIC commands with PowerShell and other modern options, including WMI’s COM API, .NET libraries and scripting languages.

READ
Microsoft Confirms Defender ShieldBreak Zero-Day, Patch in Development

One of the major reasons for removing WMIC is security. The utility has long been classified as a living-off-the-land binary, or LOLBIN, because it is a legitimate, Microsoft-signed Windows component that attackers could abuse to perform malicious actions without introducing their own tools.

Ransomware operators, for example, have frequently used WMIC commands to delete Shadow Volume Copies. Removing those recovery copies can make it much harder for victims to restore encrypted files after a ransomware attack.

Attackers have also abused WMIC to identify installed antivirus and security products and, in some cases, attempt to uninstall them. Other malware has used WMIC to add exclusions to Microsoft Defender, helping malicious files avoid detection after a system has been compromised.

With WMIC now being removed from newer Windows installations, Microsoft is eliminating a legacy component that has repeatedly been exploited as part of Windows attacks while encouraging administrators to move to newer management and scripting technologies.


Buy ExpressVPN with PayPal or Credit Card

Advertisement