Feed›OS Security›Microsoft starts removing WMIC tool used by cybercriminals...
OS SecurityBleeping Computer
6.0 — HIGH

Microsoft starts removing WMIC tool used by cybercriminals

📅 18 August 2026 at 08:12 UTC📰 Bleeping ComputerView original source ↗
Microsoft starts removing WMIC tool used by cybercriminals

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Microsoft has removed the WMIC tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds, in an effort to improve the operating system's security by thwarting a wide range of malware and attack tactics. This move aims to prevent malicious activities such as deleting Shadow Volume Copies, querying installed security solutions, and adding exclusions to Microsoft Defender.

⚙️Technical Details
Affected Systems
Windows 11 24H2Windows 11 25H2Windows 11 beta builds
Attack Vectors
LOLBIN (living-off-the-land binary) attacks
💥Impact Assessment
Severity: high
Who Is at Risk
Windows users who run WMIC command-line utilitySeverity: high
🛡️Recommended Actions
1Use alternative tools such as PowerShell and WMI's COM API for tasks previously done with WMIC
2Keep Windows Management Instrumentation (WMI) up to date
3Monitor systems for potential malicious activity
📦Affected Products
Windows 11

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed