Description

CSEs are components that generally will be executed with very high privileges on a domain machine during the GPO application. Hence, it is essential to ensure that every Client-Side Extension (CSE) contained in a GPO is sane and has been certified by a trusted party.

It is also crucial that all GPO files retrieved by domain computers originate from a safe place, before anything is applied.

Solution

You should identify unknown CSEs in the registry of a machine that applies the GPO, remove those that are dangerous, and whitelist those that you confirmed as legitimate. The GpcFileSysPath attribute should point towards a safe location such as the SYSVOL share.

See Also

Microsoft Open Specification on Group Policy Object

Microsoft Open Specification on Client-Side Extension

Additional explanations about GPOs and their dangers

MS15-011 bulletin regarding "UNC Hardened Access"

GPOddity: exploiting Active Directory GPOs through NTLM relaying, and more!

Sending GPOs Down the Wrong Track-Redirecting the GPT

Exploiting AD gpLink for Good or Evil

Abusing Client-Side Extensions (CSE): A Backdoor into Your AD Environment

Indicator Details

Name: GPO Execution Sanity

Codename: C-GPO-EXEC-SANITY

Severity: High

Type: Active Directory Indicator of Exposure

Family: Policy and Configuration

MITRE ATT&CK Information:

Attacker Known Tools

Synacktiv: GPOddity