79.1 (L1) Ensure 'Enable Sudo' is set to 'Sudo is disabled'

Information

This policy setting configures the use of the sudo.exe command line tool. The sudo feature in Windows allows users to run elevated commands (as an administrator) directly from an unelevated console session.

The recommended state for this setting is: Sudo is disabled

Sudo for Windows could be exploited for escalation of privilege and spoofing attacks by a malicious actor. For example, in October 2024,

CVE-2024-43571

(spoofing vulnerability) was created by Microsoft.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Sudo is disabled

Sudo\Enable Sudo

Impact:

The sudo.exe command line tool will not be available on the system.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 9367dbcd53262a1d3d3b803722c21e22b851c2c410759fd9bbe3aa2b665ff161