NtSetInformationVirtualMemory
NTSTATUS __stdcall NtSetInformationVirtualMemory(
VOID *ProcessHandle,
_VIRTUAL_MEMORY_INFORMATION_CLASS VmInformationClass,
UINT64 NumberOfEntries,
_MEMORY_RANGE_ENTRY *VirtualAddresses,
VOID *VmInformation,
UINT64 VmInformationLength){
VOID *v9;
char v10;
int v11;
NTSTATUS valid;
__int64 v13;
NTSTATUS result;
_ETHREAD *CurrentThread;
_DWORD *v16;
INT8 PreviousMode;
UINT64 v18;
char *v19;
unsigned __int64 v20;
_MEMORY_RANGE_ENTRY *p_VirtualAddressesa;
int v22;
__int32 v23;
__int32 v24;
char *v25;
VOID *v26;
_ETHREAD *v27;
_IO_PRIORITY_HINT IoPriorityThread;
int v29;
int v30;
NTSTATUS v31;
UINT64 v32;
INT64 v33;
__int32 v34;
__int32 v35;
int v36;
UINT64 Tag;
INT8 AccessMode;
char *Pool;
unsigned int v41;
unsigned int v42;
char v43;
PVOID Object;
__int64 v45;
PVOID P;
int v47;
PADAPTER_OBJECT DmaAdapter;
VOID *Address[2];
_HANDLE v50[4];
__int64 v51;
PVOID v52;
_ETHREAD *Thread;
VOID *v54;
VOID *Src;
_KAPC_STATE ApcState;
char v57[256];
_MEMORY_RANGE_ENTRY VirtualAddressesa;
Src = VirtualAddresses;
v9 = ProcessHandle;
v54 = ProcessHandle;
Object = 0i64;
memset(&ApcState, 0, sizeof(ApcState));
LODWORD(v45) = 0;
DmaAdapter = 0i64;
v10 = 0;
v43 = 0;
v11 = 0;
v47 = 0;
Pool = v57;
valid = 0;
v41 = 0;
if( VmInformationClass < VmPrefetchInformation )
return -1073741584;
if( VmInformationClass > VmPagePriorityInformation )
{
if( VmInformationClass == VmCfgCallTargetInformation )
{
v13 = (unsigned int)VmInformationLength;
if( (_DWORD)VmInformationLength == 40 )
goto LABEL_11;
return -1073741580;
}
if( VmInformationClass > 6 )
return -1073741584;
}
if( !VmInformation )
return -1073741581;
v13 = (unsigned int)VmInformationLength;
if( (_DWORD)VmInformationLength != 4 )
return -1073741580;
if( VmInformationClass == (_DWORD)VmInformationLength )
{
if( !MiUserHotPatchReserveSize )
return -1073741637;
if( NumberOfEntries != 1 )
return -1073741583;
}
LABEL_11:
if( NumberOfEntries - 1 > 0xFFFFFFFFFFFFFFEi64 )
return -1073741583;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
Thread = CurrentThread;
v16 = CurrentThread->Tcb.ApcState.Process->Pcb.gap0;
P = v16;
if( VmInformationClass == VmCfgCallTargetInformation && (v16[628] & 0x100) != 0 )
{
if( (CurrentThread->CrossThreadFlags & 0x40000) == 0 )
v10 = 1;
v43 = v10;
}
*(_OWORD *)Address = 0i64;
*(_OWORD *)v50 = 0i64;
v51 = 0i64;
PreviousMode = CurrentThread->Tcb.PreviousMode;
AccessMode = PreviousMode;
if( PreviousMode )
{
v18 = NumberOfEntries;
if( 16 * NumberOfEntries )
{
if( ((unsigned __int8)VirtualAddresses & 3) != 0 )
ExRaiseDatatypeMisalignment();
if( (unsigned __int64)&VirtualAddresses[v18] > 0x7FFFFFFF0000i64 || &VirtualAddresses[v18] < VirtualAddresses )
MEMORY[0x7FFFFFFF0000] = 0;
}
if( VmInformationClass == VmCfgCallTargetInformation )
{
if( (_DWORD)v13 )
{
if( ((unsigned __int8)VmInformation & 3) != 0 )
ExRaiseDatatypeMisalignment();
v19 = (char *)VmInformation + v13;
if( (unsigned __int64)v19 > 0x7FFFFFFF0000i64 || v19 < VmInformation )
MEMORY[0x7FFFFFFF0000] = 0;
}
*(_OWORD *)Address = *(_OWORD *)VmInformation;
*(_OWORD *)v50 = *((_OWORD *)VmInformation + 1);
v51 = *((_QWORD *)VmInformation + 4);
v42 = _mm_cvtsi128_si32(*(__m128i *)Address);
if( !v42 || HIDWORD(Address[0]) )
return -1073741581;
ProbeForWrite((UINT64)Address[1], 4i64, 4i64);
if( (v50[0] & 3) != 0 )
ExRaiseDatatypeMisalignment();
v20 = *(_QWORD *)v50 + 16i64 * v42;
if( v20 > 0x7FFFFFFF0000i64 || v20 < *(_QWORD *)v50 )
MEMORY[0x7FFFFFFF0000] = 0;
PreviousMode = AccessMode;
}
else
{
if( ((unsigned __int8)VmInformation & 3) != 0 )
ExRaiseDatatypeMisalignment();
v41 = *(_DWORD *)VmInformation;
v42 = (unsigned int)Address[0];
}
v16 = P;
v9 = ProcessHandle;
goto LABEL_42;
}
if( VmInformationClass != VmCfgCallTargetInformation )
{
v41 = *(_DWORD *)VmInformation;
v42 = (unsigned int)Address[0];
goto LABEL_42;
}
*(_OWORD *)Address = *(_OWORD *)VmInformation;
*(_OWORD *)v50 = *((_OWORD *)VmInformation + 1);
v51 = *((_QWORD *)VmInformation + 4);
v42 = _mm_cvtsi128_si32(*(__m128i *)Address);
if( !v42 || HIDWORD(Address[0]) )
return -1073741581;
LABEL_42:
if( v9 == (VOID *)-1i64 )
{
Object = v16;
}
else
{
LODWORD(Tag) = 1716546893;
result = ObReferenceObjectByHandleWithTag(
v9,
8ui64,
(_OBJECT_TYPE *)PsProcessType,
PreviousMode,
Tag,
&Object,
0i64);
valid = result;
if( result < 0 )
return result;
}
p_VirtualAddressesa = &VirtualAddressesa;
P = &VirtualAddressesa;
if( NumberOfEntries > 0x10 )
{
p_VirtualAddressesa = (_MEMORY_RANGE_ENTRY *)MiAllocatePool(64i64, 16 * NumberOfEntries, 0x724D6D4Dui64);
P = p_VirtualAddressesa;
if( !p_VirtualAddressesa )
{
p_VirtualAddressesa = &VirtualAddressesa;
valid = -1073741670;
v25 = v57;
goto LABEL_82;
}
}
if( VmInformationClass == VmCfgCallTargetInformation )
{
if( v42 > 0x10 )
{
Pool = (char *)MiAllocatePool(64i64, 16i64 * v42, 0x724D6D4Dui64);
if( !Pool )
{
v25 = v57;
valid = -1073741670;
goto LABEL_82;
}
}
if( *(_QWORD *)&v50[2] )
{
v52 = 0i64;
valid = ObReferenceObjectByHandle(*(VOID **)&v50[2], 1ui64, MmSectionObjectType, AccessMode, &v52, 0i64);
DmaAdapter = (PADAPTER_OBJECT)v52;
if( valid < 0 )
goto LABEL_81;
}
}
memmove(p_VirtualAddressesa, Src, 16 * NumberOfEntries);
if( VmInformationClass == VmCfgCallTargetInformation )
memmove(Pool, *(const VOID **)v50, 16 * v42);
if( Thread->Tcb.ApcState.Process != Object )
{
if( (unsigned int)(VmInformationClass - 3) <= 1 )
{
valid = -1073741585;
goto LABEL_81;
}
KeStackAttachProcess((PRKPROCESS)Object, &ApcState);
v11 = 1;
}
if( !MiValidateMemoryRangeEntries(p_VirtualAddressesa, NumberOfEntries, 0i64) )
goto LABEL_104;
if( VmInformationClass == VmPrefetchInformation )
{
if( v41 == v22 )
{
MiGetEffectivePagePriorityThread(Thread);
IoPriorityThread = PsGetIoPriorityThread(v27);
v30 = 17408;
if( IoPriorityThread > IoPriorityLow )
v30 = 0x4000;
v31 = MiPrefetchVirtualMemory(
NumberOfEntries,
(INT64)p_VirtualAddressesa,
(CHAR *)Object + 1664,
v29 | (unsigned int)v30);
goto LABEL_80;
}
goto LABEL_87;
}
v23 = VmInformationClass - 1;
if( !v23 )
{
if( v41 > 5 )
goto LABEL_87;
v32 = v41;
v33 = 1i64;
goto LABEL_85;
}
v24 = v23 - 1;
if( v24 )
{
v34 = v24 - 1;
if( v34 )
{
v35 = v34 - 1;
if( v35 )
{
v36 = v35 - 1;
if( v36 )
{
if( v36 != 1 )
goto LABEL_81;
if( v41 != v22 )
{
valid = -1073741811;
goto LABEL_81;
}
v31 = VmPrefetchVirtualAddresses(p_VirtualAddressesa);
goto LABEL_80;
}
if( v41 == 512 )
{
if( !SeSinglePrivilegeCheck(*(_QWORD *)&SeLockMemoryPrivilege, AccessMode) )
{
valid = -1073741727;
goto LABEL_81;
}
v31 = MiProcessVaContiguityInformation((UINT64)p_VirtualAddressesa, NumberOfEntries);
goto LABEL_80;
}
LABEL_115:
valid = -1073741637;
goto LABEL_81;
}
if( v41 == 1 )
{
if( *(_QWORD *)&p_VirtualAddressesa->NumberOfBytes == 4096i64 )
{
v31 = MiSetImageHotPatchAllowed((UINT64)p_VirtualAddressesa->VirtualAddress);
goto LABEL_80;
}
LABEL_104:
valid = -1073741582;
goto LABEL_81;
}
LABEL_87:
valid = -1073741581;
goto LABEL_81;
}
if( v41 != v22 )
goto LABEL_87;
if( (*((_DWORD *)Object + 281) & 0x10) == 0 )
goto LABEL_115;
v32 = 0i64;
v33 = 3i64;
LABEL_85:
v31 = MiProcessVaRangesInfoClass(NumberOfEntries, p_VirtualAddressesa, v33, v32);
LABEL_80:
valid = v31;
LABEL_81:
v25 = Pool;
goto LABEL_82;
}
v25 = Pool;
if( NumberOfEntries == 1 )
{
valid = MiCfgMarkValidEntries(
(_EPROCESS *)Object,
p_VirtualAddressesa->VirtualAddress,
*(_QWORD *)&p_VirtualAddressesa->NumberOfBytes,
Pool,
v42,
(__int64)&v45,
v43,
(_SECTION *)DmaAdapter,
v51);
if( v11 )
KeUnstackDetachProcess(&ApcState);
LOBYTE(v11) = 0;
*(_DWORD *)Address[1] = v45;
v26 = ProcessHandle;
goto LABEL_59;
}
valid = -1073741582;
LABEL_82:
v26 = ProcessHandle;
LABEL_59:
if( (v11 & 1) != 0 )
KeUnstackDetachProcess(&ApcState);
if( DmaAdapter )
HalPutDmaAdapter(DmaAdapter);
if( v26 != (VOID *)-1i64 )
ObfDereferenceObjectWithTag(Object, 0x66506D4Dui64);
if( p_VirtualAddressesa != &VirtualAddressesa )
ExFreePoolWithTag(p_VirtualAddressesa, 0);
if( v25 != v57 )
ExFreePoolWithTag(v25, 0);
return valid;
}Referenced by:
No references.