A newly patched Active Directory flaw let standard domain users impersonate domain controllers and forge authentication tokens.