MiForceCrashForInvalidAccess

NTSTATUS __stdcall MiForceCrashForInvalidAccess(PEPROCESS Process){
  _ADAPTER_OBJECT *CurrentThread; 
  signed __int32 bf_0; 
  signed __int32 v4; 
  VOID *P3; 
  NTSTATUS result; 
  VOID *CallbackContext; 
  VOID *StackSize; 
  INT64 *MaximumStackSize; 
  PS_ATTRIBUTE_LIST *AttributeList; 
  const _GUID *v11; 
  _OBJECT_ATTRIBUTES ObjectAttributes; 
  UINT64 v13[19]; 
  VOID *ThreadHandle; 
  PVOID Object; 

  ThreadHandle = 0i64;
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  CurrentThread = (_ADAPTER_OBJECT *)KeGetCurrentThread();
  --WORD2(CurrentThread->WorkItem.List.Blink);
  if( *(&CurrentThread->LowMemoryLogicalAddressQueueInUse + 2) == 1
    || (*(&CurrentThread->AdapterObject.CrashDump.ScatterHint.Offset + 1) & 0x400) != 0 )
  {
    _m_prefetchw(&Process->1120);
    bf_0 = Process->$4E3DFAFA17165B33969DFF4E60E4EB31::_bf_0;
    do
    {
      v4 = bf_0;
      bf_0 = _InterlockedCompareExchange((volatile signed __int32 *)&Process->1120, bf_0 | 0x4000000, bf_0);
    }
    while( v4 != bf_0 );
    if( (bf_0 & 0x4000000) == 0 )
    {
      if( (IoThreadToProcess((PETHREAD)CurrentThread)->Flags3 & 0x1000) != 0 )
      {
        P3 = PsGetProcessId(Process);
        LODWORD(StackSize) = 0;
        DbgkWerCaptureLiveKernelDump(
          L"MemoryManager",
          0x1Aui64,
          0x9000ui64,
          0xFFFFFFFFC0000726ui64,
          (UINT64)P3,
          0i64,
          0i64,
          0i64,
          StackSize,
          MaximumStackSize,
          AttributeList,
          v11,
          *(VOID **)&ObjectAttributes.Length,
          (UINT64)ObjectAttributes.RootDirectory,
          (UINT64)ObjectAttributes.ObjectName,
          *(UINT64 *)&ObjectAttributes.Attributes,
          (UINT64)ObjectAttributes.SecurityDescriptor,
          (UINT64)ObjectAttributes.SecurityQualityOfService,
          v13[0],
          (VOID *)v13[1],
          (DBGK_LIVEDUMP_FLAGS)v13[2]);
      }
      else
      {
        memset(v13, 0i64, sizeof(v13));
        LODWORD(v13[0]) = -1073739994;
        LODWORD(v13[3]) = 1;
        v13[4] = (UINT64)PsGetProcessId(Process);
        DbgkQueueUserExceptionReport(CurrentThread);
      }
      PsFreezeProcess(Process, 0);
      LODWORD(CallbackContext) = 1;
      ObjectAttributes.Length = 48;
      ObjectAttributes.RootDirectory = 0i64;
      ObjectAttributes.Attributes = 512;
      ObjectAttributes.ObjectName = 0i64;
      *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
      if( ZwCreateThreadEx(
             &ThreadHandle,
             0x1FFFFFui64,
             &ObjectAttributes,
             (VOID *)0xFFFFFFFFFFFFFFFFi64,
             0i64,
             0i64,
             (UINT64)CallbackContext,
             0i64,
             0x1000ui64,
             0x1000ui64,
             0i64) < 0 )
      {
        PsTerminateProcess((ULONG_PTR)Process, 0xC0000725ui64);
      }
      else
      {
        Object = 0i64;
        ObReferenceObjectByHandle(ThreadHandle, 0x1FFFFFui64, (_OBJECT_TYPE *)PsThreadType, 0, &Object, 0i64);
        KeRequestTerminationProcess((_KTHREAD *)Object, 3i64);
        ObCloseHandle(ThreadHandle, 0);
        HalPutDmaAdapter((PADAPTER_OBJECT)Object);
      }
    }
  }
  else
  {
    KeRequestTerminationProcess((_KTHREAD *)CurrentThread, 2i64);
  }
  KeLeaveCriticalRegionThread((_KTHREAD *)CurrentThread);
  return result;
}

Referenced by:

MiKernelWriteToExecutableMemory