Microsoft pulls a 30-year-old Windows tool that hackers loved

WMIC, a command-line utility abused by ransomware crews to wipe backups and disable antivirus, is gone from fresh installs of Windows 11 24H2 and 25H2.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A Windows command prompt window showing WMIC utility commands being executed, with a removal or deprecation notification overlaying the interface, representing
Share

Key points

  • Microsoft has removed WMIC, the Windows Management Instrumentation Command-line tool, from new installs of Windows 11 versions 24H2 and 25H2.
  • It's no longer available as an optional add-on, called a Feature on Demand, as of this week's change.
  • WMIC was deprecated in 2016 on Windows Server 2012 and again in 2021 on Windows 10 21H1, so this removal has been telegraphed for years.
  • Ransomware gangs routinely used it to delete Windows backup snapshots, uninstall antivirus, or add Defender exclusions so malware ran unnoticed.
  • Windows Management Instrumentation itself, the underlying system WMIC talked to, is not affected. Only the command-line front end is gone.

Microsoft has finally pulled the plug on WMIC, a decades-old command-line tool that criminals used to disable defences on Windows machines before locking them up for ransom.

The change landed this week in Windows 11 versions 24H2 and 25H2, plus current beta builds. First reported by BleepingComputer, the removal means fresh installs no longer ship the utility and it can't be added back as an optional Windows component. Microsoft announced in September that WMIC would be removed after upgrading to Windows 11 25H2 and later.

What exactly did Microsoft remove?

Microsoft removed WMIC, short for Windows Management Instrumentation Command-line: a built-in text-based tool that lets an administrator ask Windows questions and change settings by typing commands.

The underlying plumbing it spoke to, called Windows Management Instrumentation (WMI), stays put. Only the old front end is gone. Modern equivalents such as PowerShell, WMI's COM API, and .NET libraries do the same jobs and are what Microsoft points administrators toward instead.

WMIC was deprecated (marked as "do not rely on this") in Windows Server 2012 back in 2016, then in Windows 10 21H1 in 2021. It became a Feature on Demand in 2022, meaning it wasn't installed by default but could be added. January 2024 brought Microsoft's announcement that it would be removed altogether. This week it was.

Why did the hackers like it so much?

WMIC was a favourite because it was Microsoft-signed and trusted by security software. Attackers didn't need to smuggle in their own tools. They could just use the one Windows shipped with.

Security researchers call this pattern a LOLBIN, short for "living off the land binary." A burglar who uses the homeowner's own kitchen knife is harder to spot than one who brings a crowbar.

In practice, that looked like this:

Attack step What WMIC was used for
Preparing a ransomware hit Deleting Shadow Volume Copies, the backup snapshots Windows keeps, so victims can't restore files
Scouting the machine Listing installed antivirus and security products
Disabling defences Uninstalling antivirus or adding folders to Microsoft Defender's exclusion list so malware runs unnoticed

Strip WMIC out and a lot of off-the-shelf ransomware scripts simply break. Attackers can still do these things through PowerShell or WMI programming interfaces, but they have to write new tooling, and defenders have fewer familiar commands to watch for.

Should home users and businesses do anything?

Home users don't need to lift a finger. Install Windows 11 24H2 or 25H2 fresh and WMIC won't be there.

Businesses face real work. Any old script or software installer that calls wmic.exe will fail on a clean install. IT teams should search their estate for those calls now and rewrite them before rolling out the new builds.

One caveat: machines upgraded from earlier Windows 11 versions may still have WMIC present until the change catches up with them. Don't assume it's gone just because the release notes say so.

This is a quiet win for defenders. We've tracked WMIC abuse as part of our attack surface reduction coverage since August, and the pattern is consistent: Microsoft's own legacy tooling keeps showing up in incident reports long after the vendor has flagged it for removal. Closing this particular door took the better part of a decade. Watch whether attackers shift volume toward PowerShell-based equivalents, because the underlying WMI access hasn't gone anywhere.

© 2026 Threat Vectr