That's true. However, it's possible to do it with two co-created certificates (http://www.schneier.com/blog/archives/2008/12/forging_ssl_ce...), and depending on how the licensing process works, that could easily have been done. I would imagine that the creators of Flame have more than enough computing power to do that.
The articles though seem to be suggesting that the "real" certificates were being granted with too many powers. Microsoft's advisory seems to suggest that both were potentially used (MD5 collisions and overly-broad purposes on real certificates). It's hard to tell what really happened here...
The articles though seem to be suggesting that the "real" certificates were being granted with too many powers. Microsoft's advisory seems to suggest that both were potentially used (MD5 collisions and overly-broad purposes on real certificates). It's hard to tell what really happened here...