Interestana
Home/News/Microsoft Removes WMIC Tool to Thwart Cybercriminals
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Microsoft Removes WMIC Tool to Thwart Cybercriminals

Microsoft announced the removal of the Windows Management Instrumentation Command-line (WMIC) tool from specific Windows 11 builds, including Windows 11 24H2 and 25H2, as well as beta builds released this week. This action is a proactive measure to disrupt the activities of cybercriminals who have been exploiting the WMIC tool for malicious purposes. The WMIC tool, part of the Windows Management Instrumentation (WMI) framework, is a legitimate command-line utility designed for system administration tasks, allowing users to manage Windows operating systems and applications. However, its capabilities have been co-opted by threat actors. Specifically, threat actors have utilized WMIC to execute malicious commands and scripts remotely, often as part of post-exploitation activities after gaining initial access to a system. This can include downloading and executing further malware, disabling security features, or exfiltrating data. By removing WMIC from these Windows 11 versions, Microsoft aims to eliminate a critical vector that attackers have leveraged to maintain persistence and expand their reach within compromised networks. The company's decision reflects an ongoing effort to bolster Windows security by identifying and mitigating tools that, while intended for legitimate use, are frequently abused by malicious actors. This move is part of a broader strategy to enhance the security posture of the Windows operating system against evolving cyber threats. The WMIC tool's removal is expected to make it more difficult for attackers to perform certain reconnaissance and execution actions that were previously facilitated by this utility. Users who relied on WMIC for legitimate administrative tasks may need to explore alternative methods for system management, such as PowerShell or other scripting languages, which offer similar functionalities but may be less susceptible to the specific exploitation methods observed with WMIC. Microsoft has not specified an exact date for the removal from all versions of Windows, but its inclusion in the latest stable and beta releases indicates a firm commitment to phasing out the tool's availability in its most current operating system offerings. The company's security advisories have previously highlighted the misuse of WMIC, underscoring the need for this decisive action. This development is significant for cybersecurity professionals and organizations as it removes a known tool from the attacker's arsenal, potentially forcing them to adapt their tactics, techniques, and procedures (TTPs). The WMIC tool's functionality is deeply integrated with the Windows operating system, making its removal a notable change in the system's architecture for administrative purposes. The Windows Management Instrumentation (WMI) itself remains a core component of Windows, and the removal specifically targets the command-line interface for interacting with it, rather than the entire WMI framework.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next