This is only a problem if a client application has a server certificate pinned in source code. Otherwise, you can create a cert with a privacy CA and add it to a desktop OS trusted cert store.
0: https://hugotunius.se/2020/08/07/stealing-tls-sessions-keys-...