1 article on this topic.
A public exploit shows how a certificate-enrollment fallback in AD CS let any authenticated domain user forge a Domain Controller identity and pull the krbtgt secret via DCSync.