I'm a bit confused by the sudo tag; it seems to imply that commands run with sudo get elevated privileges... which is kinda the point...
As a slightly contrived example, imagine you allow someone to use "apt-get update" with sudo, reasoning that it only changes a local index and doesn't alter the system. You don't allow them to use sudo for anything else.
If they run "sudo apt-get update -o APT::Update::Pre-Invoke::=/bin/sh" they get a shell that lets them execute any command as root, not just the command you gave them permission for.
That can look safe at first glance, but then you can exploit that binaries to get some other unexpected results:
Change your mount binary for a privileged shell: sudo mount -o bind /bin/sh /bin/mount
Run a privileged shell from inside vim: sudo vi -c ':!/bin/sh' /dev/null
And so on...