18.9.52 (L1) Ensure 'Configure the behavior of the sudo command' is set to 'Enabled: Disabled'

Information

This policy setting configures the use of the sudo.exe command line tool. The sudo feature in Windows allows users to run elevated commands (as an administrator) directly from an unelevated console session.

The recommended state for this setting is: Enabled: Disabled

Sudo for Windows could be exploited for escalation of privilege and spoofing attacks by a malicious actor. For example, in October 2024,

CVE-2024-43571

(spoofing vulnerability) was created by Microsoft.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Disabled :

Computer Configuration\Policies\Administrative Templates\System\Configure the behavior of the sudo command

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template Sudo.admx that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

The sudo.exe command line tool will not be available on the system.

See Also

https://workbench.cisecurity.org/benchmarks/22007

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: f8281bf96f06680aaf977e95ec2ff6471ee941931c6e3db5f9d320c7e758c479