Microsoft has announced that it plans to discontinue VBScript in the second half of 2024 by turning it into an on-demand feature before eventually removing it completely.
Windows has several on-demand features (FODs), including Hyper-V Windows Subsystem for Linux, .NET Framework and others. These features are not installed by default on the Windows operating system, but they can be added on as needed.
Microsoft plans to phase out VBScript to make room for “more powerful and versatile scripting languages such as JavaScript and PowerShell.” The decision is motivated by the broader range of capabilities of those languages and their better suitability to web development and automation tasks.
"Beginning with the new OS release slated for later this year, VBScript will be available as features on demand (FODs),” said Microsoft program manager Naveen Shankar. “The feature will be completely retired from future Windows OS releases, as we transition to the more efficient PowerShell experiences.”
According to the company’s advisory, the phaseout will happen in three phases. In the first phase, VBScript will be enabled as an optional feature by default in Windows 11 24H2, the second will prevent the feature from being pre-installed, and the third will completely eliminate the feature from future versions of Windows.
All VBScript dynamic link libraries (DLLs) will be eliminated, rendering projects that rely on VBScript obsolete.
Although the advisory emphasizes the need for more capable scripting languages, Microsoft’s move also impacts cybersecurity. Threat actors often rely on VBScript to deliver malware strains, including Emotet, Lokibot, Qbot and others.
The company’s decision to phase it out will remove Windows and Office features commonly exploited by threat actors to deliver malware on vulnerable systems.
Dedicated solutions like Bitdefender Ultimate Security can boost your defenses against VBScript attacks and other digital intrusions, including worms, viruses, Trojans, spyware, rootkits, zero-day exploits, and ransomware.
It encompasses a comprehensive suite of advanced security features that can thwart digital intruders’ attempts to compromise your device, including real-time monitoring and protection, a network threat prevention module, email protection, and multi-layered ransomware protection technology.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all postsNovember 14, 2024
September 06, 2024