Information
This policy setting configures the use of the sudo.exe command line tool. The sudo feature in Windows allows users to run elevated commands (as an administrator) directly from an unelevated console session.
The recommended state for this setting is: Sudo is disabled
Sudo for Windows could be exploited for escalation of privilege and spoofing attacks by a malicious actor. For example, in October 2024,
CVE-2024-43571
(spoofing vulnerability) was created by Microsoft.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Sudo is disabled
Sudo\Enable Sudo
Impact:
The sudo.exe command line tool will not be available on the system.