Most info I can get on this is through a reverse engineer done in 2004 of the RDP (http://efod.se/media/thesis.pdf), it was established that when terminal services set up in Application Server Mode(i.e. corporate environments) its configured to sign requests using the x509 protocol. Wouldn't be much of a stretch to extract the certificates used if they were configured incorrectly. My guess is that due to this being engineered as a licensing issue (i.e. DRM added after the fact and not as a trust issue) corporates weren't issued with specific certs, theres very little that could be done to trace down the point where this leaked.