Information
This policy setting configures the use of the sudo.exe command line tool. The sudo feature in Windows allows users to run elevated commands (as an administrator) directly from an unelevated console session.
The recommended state for this setting is: Enabled: Disabled
Sudo for Windows could be exploited for escalation of privilege and spoofing attacks by a malicious actor. For example, in October 2024,
CVE-2024-43571
(spoofing vulnerability) was created by Microsoft.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Disabled :
Computer Configuration\Policies\Administrative Templates\System\Configure the behavior of the sudo command
Note: This Group Policy path may not exist by default. It is provided by the Group Policy template Sudo.admx that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).
Impact:
The sudo.exe command line tool will not be available on the system.