Microsoft is bringing the Linux sudo command to Windows Server

  • February 4, 2024
  •  
  • 12:26 PM
  •  
  • 4

Windows Server

Microsoft is bringing the Linux 'sudo' feature to Windows Server 2025, offering a new way for admins to elevate privileges for console applications.

Superuser do, or sudo, is a Linux console program that allows low-privileged users to execute a command with elevated privileges, usually as root.

This command offers increased security in Linux as servers can be used normally under low-privileged accounts while still allowing users to elevate their privileges as needed when running specific commands.

An example of the sudo command is shown below, where we run 'whoami' as a low-privileged user and then run it using sudo.

Notice that the whoami command shows that I am running it as the bleeping user. However, when I execute whoami with sudo, it elevates my privileges to root.

Demonstrating the sudo command using whoami
Demonstrating the sudo command using whoami
Source: BleepingComputer

Testing sudo in Windows Server 2025

Microsoft released the first Windows Server 2025 Insider preview build last week. However, soon after, a newer version was leaked online.

As first reported by Windows Latest (first spotted by @thebookisclosed), the leaked version contains some new in-development features, including new settings for a Windows 'sudo' command.

New sudo settings in Windows Server 2025 preview build
New sudo settings in Windows Server 2025 preview build
Source: WindowsLatest

These settings are only available after enabling developer mode, and the sudo command does not currently work from the command line yet, showing it is early in development.

However, the sudo settings provide some clues as to how the command will work, with the ability to run sudo applications 'In a new windows', 'With input disabled', and 'Inline'.

Windows already offers the ability to elevate programs automatically using UAC prompts, causing the programs to run with elevated privileges in their own window.

However, some administrative tools, such as bcdedit and reagentc, require you to be an administrator to run these commands.

In these cases, the sudo command will allow the programs to run based on its Windows settings, such as in a new window, inline in the current window, or possibly in a non-interactive shell using the disabled input setting.

While this feature has not been spotted in Windows 11, it would not be surprising for Microsoft to add sudo to that operating system in the future as well.

It is important to note that Microsoft commonly tests new features in preview builds that do not make it into the production builds.

However, it will be interesting to see how Microsoft integrates this feature into Windows and will be something to keep an eye on.

Update 2/5/24: Updated article with info on it first being spotted by Albacore.

Αναζήτηση
Κατηγορίες
Διαβάζω περισσότερα
Hacker arrested for selling bank accounts of US and Canadian users
February 18, 2024   10:06 AM   0 Ukraine's cyber police arrested a...
από AFFA 2024-02-18 17:12:48 0 153
Iranian hackers pose as journalists to push backdoor malware
May 4, 2024   10:17 AM   0 The Iranian state-backed threat actor...
από AFFA 2024-05-04 15:25:03 0 21
Google now pays up to $450-Thousand Dollars for RCE bugs in some Android apps
April 30, 2024   02:33 PM   0 Google has increased rewards for...
από AFFA 2024-05-01 15:36:07 0 22
US charges two more suspects with DraftKing account hacks
January 30, 2024   04:28 PM   1 ​The U.S. Department of Justice...
από AFFA 2024-01-31 19:15:59 0 146
Windows 11 24H2 upgrades Bluetooth accessories’ discoverability
Windows 11 24H2 intends to change the way of discovering nearby Bluetooth devices. Currently,...
από AFFA 2024-02-17 17:25:48 0 138