SeSetSecurityAttributesTokenEx

NTSTATUS __stdcall SeSetSecurityAttributesTokenEx(
        VOID *TokenHandle,
        CHAR PreviousMode,
        _UNICODE_STRING *PlaceHolderAttrib,
        UINT8 TrySingleInstance,
        _TOKEN_SECURITY_ATTRIBUTE_OPERATION *pOperations,
        _TOKEN_SECURITY_ATTRIBUTES_INFORMATION *pAttributes,
        UINT8 *SingleInstanced){
  int v7; 
  INT64 v8; 
  _ETHREAD *CurrentThread; 
  PERESOURCE *v10; 
  PVOID v11; 
  NTSTATUS ProcUniqueLuidAndIndexFromToken; 
  _TOKEN_SECURITY_ATTRIBUTES_INFORMATION *v13; 
  _TOKEN_SECURITY_ATTRIBUTE_OPERATION *v14; 
  _TOKEN_SECURITY_ATTRIBUTE_OPERATION *v15; 
  signed __int32 v17[8]; 
  PVOID Object; 
  __int64 v19; 
  unsigned int v20; 

  v19 = 0i64;
  v20 = 0;
  if( PlaceHolderAttrib )
    return -1073741811;
  if( !TrySingleInstance || (*(&stru_140CF2E80 + 7296) & 3) != 3 )
  {
    v15 = pOperations;
    *SingleInstanced = 0;
    return SepInternalSetSecurityAttributesToken(TokenHandle, PreviousMode, 1u, v15, pAttributes);
  }
  if( PreviousMode )
    return -1073741790;
  Object = 0i64;
  v7 = ObReferenceObjectByHandle(TokenHandle, 0x80ui64, (_OBJECT_TYPE *)SeTokenObjectType, 0, &Object, 0i64);
  if( v7 >= 0 )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --CurrentThread->Tcb.KernelApcDisable;
    v10 = (PERESOURCE *)Object;
    ExAcquireResourceExclusiveLite(*((_QWORD *)Object + 6), 1, v8);
    _InterlockedOr(v17, 0);
    v11 = Object;
    ProcUniqueLuidAndIndexFromToken = SepGetProcUniqueLuidAndIndexFromTokenEx(
                                        1,
                                        (INT64)Object,
                                        (_XSTATE_CONFIGURATION *)&v20,
                                        (_XSTATE_CONFIGURATION *)&v19);
    v13 = pAttributes;
    v14 = pOperations;
    if( ProcUniqueLuidAndIndexFromToken >= 0 )
    {
      v7 = SepSetSingletonEntry(v20, (INT64 *)pOperations, (INT64)pAttributes);
      if( v7 >= 0 )
      {
        *SingleInstanced = 1;
LABEL_13:
        *((_QWORD *)v11 + 7) = ExpLuidIncrement + _InterlockedExchangeAdd64(&ExpLuid, ExpLuidIncrement);
      }
    }
    else
    {
      *SingleInstanced = 0;
      v7 = AuthzBasepSetSecurityAttributesToken(*((_FADT **)v11 + 97), v14, v13);
      if( v7 >= 0 )
        goto LABEL_13;
    }
    _InterlockedOr(v17, 0);
    ExReleaseResourceLite(v10[6]);
    KeLeaveCriticalRegionThread(KeGetCurrentThread());
  }
  if( Object )
    ObfDereferenceObjectWithTag(Object, 0x746C6644ui64);
  return v7;
}

Referenced by:

No references.