Microsoft Removes WMIC Tool From Windows 11 Due to Ransomware Abuse
Microsoft has removed the WMIC command-line tool from Windows 11 in a September update, as it was frequently abused by ransomware to prevent file recovery. The tool is no longer available as an optional feature.

Microsoft has permanently removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 in a mandatory September update. The tool was heavily abused by ransomware to destroy system recovery functionalities, such as previous backups and restore points.
WMIC is a long-standing command-line utility in Windows, designed for enterprise system management. However, it was exploited by various ransomware strains, including TeslaCrypt, Serpent, WhiteRose, and WannaCry, to delete recovery options before encrypting files, making data restoration difficult for users.
Microsoft had announced the deprecation of WMIC in 2021, but it remained available as an "on-demand feature." The September update removed it entirely. Companies still relying on WMIC are urged by Microsoft to migrate to officially supported alternative solutions.
The removal of WMIC is a significant security measure that hinders ransomware operations by eliminating a common and destructive tactic. Microsoft advises users unaware of WMIC not to attempt to reinstall it. A download package for manual restoration is available but intended only as a temporary solution for the few who critically need it.