Microsoft Removes WMIC from Windows 11 24H2 and 25H2
Microsoft has removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 versions 24H2 and 25H2, along with the latest Windows Insider beta builds.
WMIC is a legacy command-line utility that allows administrators and scripts to interact with Windows Management Instrumentation (WMI) by running text-based commands. Although the tool has been deprecated for several years, it remains widely used in older administration scripts and by malware targeting Windows systems.
The removal is part of Microsoft’s long-term plan to deprecate and eliminate WMIC from Windows. The company previously announced that the utility would be removed after users upgraded to Windows 11 25H2 or a later release.
WMIC has been deprecated for several years
Microsoft announced in January 2024 that it would deprecate WMIC in Windows Server 2012 and later versions, as well as in Windows 10 version 21H1 and later releases. Beginning with Windows 11 version 22H2, WMIC was converted into a Feature on Demand. Microsoft first disabled the tool by default before proceeding with its complete removal.
“Windows Management Instrumentation Command-line (WMIC) has been removed in this release. This change is part of the ongoing deprecation and removal of WMIC from Windows,” Microsoft said in the Windows Insider beta release notes and Windows 11 version 26H1 preview documentation.
Microsoft also confirmed that WMIC is already removed by default from new installations of Windows 11 24H2 and 25H2. The tool is no longer available as a Feature on Demand in those versions, according to the company’s release preview notes.
WMI remains available in Windows
The removal of WMIC does not affect Windows Management Instrumentation itself. WMI remains available, meaning administrators and applications can continue using the underlying management framework.
Microsoft recommends replacing WMIC commands with PowerShell and other modern technologies, including the WMI COM API, .NET libraries, and supported scripting languages. Organizations that rely on legacy WMIC scripts should update them before upgrading affected Windows devices.
Administrators can find additional migration guidance in Microsoft’s WMIC removal support documentation.
WMIC removal may disrupt malware and attack techniques
Microsoft’s decision to remove WMIC is also intended to strengthen Windows security by eliminating a trusted system utility that threat actors have frequently abused.
WMIC has long been classified as a Living-off-the-Land Binary (LOLBin). Because it is a Microsoft-signed executable, attackers have used it to perform malicious actions while blending in with legitimate administrative activity.
For example, ransomware operators commonly use WMIC commands to delete Volume Shadow Copies. Removing these backups can prevent victims from recovering encrypted files without paying a ransom.
Attackers have also used WMIC to identify installed security products, query antivirus configurations, and remove security software from compromised systems. In other attacks, malware used WMIC to add exclusions to Microsoft Defender, helping malicious files avoid detection.
Although removing WMIC will not stop every attack technique, it eliminates one widely abused tool from new Windows installations and encourages organizations to transition to more secure, modern management technologies.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




