A working exploit chain tied to Active Directory shows how certificate trust, if misbound, can let a low-privileged account speak as a machine that sits at the top of the domain.