Turns out this certificate corresponds to "Microsoft root for application signing" (selected by MICROSOFT_ROOT_CERT_CHAIN_POLICY_CHECK_APPLICATION_ROOT_FLAG) instead of default "Microsoft product root". I added a test for the flag and updated the patch accordingly.