CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Microsoft starts removing WMIC tool used by cybercriminals

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4567

As cited

Copy frozen at (site build).

vulnerabilities

Microsoft starts removing WMIC tool used by cybercriminals

Microsoft removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 builds 24H2 and 25H2, as well as from beta releases. The tool had become a common vector for cybercriminals in attack chains.

Why it matters: Organizations running Windows 11 should verify that WMIC removal does not break existing scripts or monitoring tools, as this administrative capability is now deprecated.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft starts removing WMIC tool used by cybercriminals

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft starts removing WMIC tool used by cybercriminals

Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 versions 24H2 and 25H2, as well as from recent beta builds. The tool has become a common vector for malware deployment and system compromise due to its legitimate administrative capabilities.

Why it matters: Windows administrators and security teams managing Windows 11 deployments should prepare for WMIC removal and identify alternative tools for their operational workflows before these versions reach production.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft starts removing WMIC tool used by cybercriminals

Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 versions 24H2 and 25H2, as well as from recent beta builds. The tool has become a common vector for malware deployment and system compromise due to its legitimate administrative capabilities.

Why it matters: Windows administrators and security teams managing Windows 11 deployments should prepare for WMIC removal and identify alternative tools for their operational workflows before these versions reach production.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary