SepCheckAndCopySelfRelativeSD
NTSTATUS __stdcall SepCheckAndCopySelfRelativeSD(
_SECURITY_DESCRIPTOR *SecurityDescriptorIn,
_SECURITY_DESCRIPTOR **SecurityDescriptorOut,
UINT64 *SDLength,
UINT8 *NeedToFree){
int v7;
VOID **PoolWithTag;
_SECURITY_DESCRIPTOR *v9;
PSECURITY_DESCRIPTOR AbsoluteSecurityDescriptor;
AbsoluteSecurityDescriptor = SecurityDescriptorIn;
*SecurityDescriptorOut = 0i64;
*(_DWORD *)SDLength = 0;
*NeedToFree = 0;
v7 = 0;
if( SecurityDescriptorIn )
{
if( (SecurityDescriptorIn->Control & 0x8000u) != 0 )
{
*(_DWORD *)SDLength = SepSecurityDescriptorStrictLength(SecurityDescriptorIn);
*SecurityDescriptorOut = v9;
}
else
{
v7 = RtlAbsoluteToSelfRelativeSD(&AbsoluteSecurityDescriptor, 0i64, SDLength);
if( v7 == -1073741789 )
{
PoolWithTag = ExAllocatePoolWithTag(1ui64, *(unsigned int *)SDLength, 1883333971i64);
*SecurityDescriptorOut = (_SECURITY_DESCRIPTOR *)PoolWithTag;
if( PoolWithTag )
{
v7 = RtlAbsoluteToSelfRelativeSD(AbsoluteSecurityDescriptor, PoolWithTag, SDLength);
if( v7 >= 0 )
{
*NeedToFree = 1;
}
else
{
ExFreePoolWithTag(*SecurityDescriptorOut, 0);
*SecurityDescriptorOut = 0i64;
}
}
else
{
return -1073741670;
}
}
}
}
return v7;
}Referenced by:
SeOperationAuditAlarm
SepAdtOpenObjectAuditAlarm
SepAdtStagingEvent