Language:
CSEs are components that generally will be executed with very high privileges on a domain machine during the GPO application. Hence, it is essential to ensure that every Client-Side Extension (CSE) contained in a GPO is sane and has been certified by a trusted party.
It is also crucial that all GPO files retrieved by domain computers originate from a safe place, before anything is applied.
You should identify unknown CSEs in the registry of a machine that applies the GPO, remove those that are dangerous, and whitelist those that you confirmed as legitimate. The GpcFileSysPath attribute should point towards a safe location such as the SYSVOL share.
Microsoft Open Specification on Group Policy Object
Microsoft Open Specification on Client-Side Extension
Additional explanations about GPOs and their dangers
MS15-011 bulletin regarding "UNC Hardened Access"
GPOddity: exploiting Active Directory GPOs through NTLM relaying, and more!
Sending GPOs Down the Wrong Track-Redirecting the GPT
Exploiting AD gpLink for Good or Evil
Abusing Client-Side Extensions (CSE): A Backdoor into Your AD Environment
Name: GPO Execution Sanity
Codename: C-GPO-EXEC-SANITY
Severity: High
Type: Active Directory Indicator of Exposure
Family: Policy and Configuration
Synacktiv: GPOddity