It is possible to perform a man in the middle attack considering this situation:
This is not possible if the client is checking the certificate properly. Proper validation not only checks if the certificate is signed by a trusted CA but also includes a check if the target of the request matches the subject of the certificate. In case of HTTP this means to check if the hostname in the URL is contained in the subject of the certificate.