OS SecurityBleeping Computer
6.0 — HIGH
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Microsoft has removed the WMIC tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds, in an effort to improve the operating system's security by thwarting a wide range of malware and attack tactics. This move aims to prevent malicious activities such as deleting Shadow Volume Copies, querying installed security solutions, and adding exclusions to Microsoft Defender.
⚙️Technical Details
Affected Systems
Windows 11 24H2Windows 11 25H2Windows 11 beta builds
Attack Vectors
LOLBIN (living-off-the-land binary) attacks
💥Impact Assessment
Severity: high
Who Is at Risk
Windows users who run WMIC command-line utilitySeverity: high
🛡️Recommended Actions
1Use alternative tools such as PowerShell and WMI's COM API for tasks previously done with WMIC
2Keep Windows Management Instrumentation (WMI) up to date
3Monitor systems for potential malicious activity
📦Affected Products
Windows 11
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
