:

MICROSOFT REMOVES WMIC TOOL FROM WINDOWS 11

SECURITY DESK1 MIN READ
TUE, AUG 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11, citing widespread abuse by cybercriminals. The tool is being eliminated from Windows 11 versions 24H2 and 25H2.

The WMIC utility, a command-line interface for system administration tasks, has become a favored tool for attackers executing malicious scripts and lateral movement within networks. By removing it, Microsoft aims to reduce attack surface and limit unauthorized system access. The deprecation applies to the latest Windows 11 builds, with the tool already absent from beta releases. Users relying on WMIC functionality can transition to PowerShell alternatives, which offer comparable capabilities with better security controls. This move aligns with Microsoft's broader security strategy of phasing out legacy tools exploited by threat actors. The company has previously deprecated similar utilities as part of efforts to harden Windows against evolving threats. Organizations running older Windows versions should begin planning migration strategies to PowerShell-based solutions. The removal does not affect currently supported versions immediately, providing time for compliance and transition planning.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The Clop ransomware gang created a specialized Java web shell targeting PTC Windchill and FlexPLM servers. The malware includes built-in capabilities to decrypt credentials, enumerate repositories, and exfiltrate files.

4H AGOIndustry Desk

France's tax authority plans to use artificial intelligence tools to identify vulnerabilities in its systems following a cyberattack that compromised personal data of hundreds of thousands of taxpayers.

5H AGOAI Desk

Passkeys offer stronger protection than passwords, even when paired with password managers. The shift addresses fundamental vulnerabilities in traditional authentication.

5H AGOIndustry Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability. The flaw was previously flagged as under active exploitation in April.

11H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.