MiForceCrashForInvalidAccess
NTSTATUS __stdcall MiForceCrashForInvalidAccess(PEPROCESS Process){
_ADAPTER_OBJECT *CurrentThread;
signed __int32 bf_0;
signed __int32 v4;
VOID *P3;
NTSTATUS result;
VOID *CallbackContext;
VOID *StackSize;
INT64 *MaximumStackSize;
PS_ATTRIBUTE_LIST *AttributeList;
const _GUID *v11;
_OBJECT_ATTRIBUTES ObjectAttributes;
UINT64 v13[19];
VOID *ThreadHandle;
PVOID Object;
ThreadHandle = 0i64;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
CurrentThread = (_ADAPTER_OBJECT *)KeGetCurrentThread();
--WORD2(CurrentThread->WorkItem.List.Blink);
if( *(&CurrentThread->LowMemoryLogicalAddressQueueInUse + 2) == 1
|| (*(&CurrentThread->AdapterObject.CrashDump.ScatterHint.Offset + 1) & 0x400) != 0 )
{
_m_prefetchw(&Process->1120);
bf_0 = Process->$4E3DFAFA17165B33969DFF4E60E4EB31::_bf_0;
do
{
v4 = bf_0;
bf_0 = _InterlockedCompareExchange((volatile signed __int32 *)&Process->1120, bf_0 | 0x4000000, bf_0);
}
while( v4 != bf_0 );
if( (bf_0 & 0x4000000) == 0 )
{
if( (IoThreadToProcess((PETHREAD)CurrentThread)->Flags3 & 0x1000) != 0 )
{
P3 = PsGetProcessId(Process);
LODWORD(StackSize) = 0;
DbgkWerCaptureLiveKernelDump(
L"MemoryManager",
0x1Aui64,
0x9000ui64,
0xFFFFFFFFC0000726ui64,
(UINT64)P3,
0i64,
0i64,
0i64,
StackSize,
MaximumStackSize,
AttributeList,
v11,
*(VOID **)&ObjectAttributes.Length,
(UINT64)ObjectAttributes.RootDirectory,
(UINT64)ObjectAttributes.ObjectName,
*(UINT64 *)&ObjectAttributes.Attributes,
(UINT64)ObjectAttributes.SecurityDescriptor,
(UINT64)ObjectAttributes.SecurityQualityOfService,
v13[0],
(VOID *)v13[1],
(DBGK_LIVEDUMP_FLAGS)v13[2]);
}
else
{
memset(v13, 0i64, sizeof(v13));
LODWORD(v13[0]) = -1073739994;
LODWORD(v13[3]) = 1;
v13[4] = (UINT64)PsGetProcessId(Process);
DbgkQueueUserExceptionReport(CurrentThread);
}
PsFreezeProcess(Process, 0);
LODWORD(CallbackContext) = 1;
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 512;
ObjectAttributes.ObjectName = 0i64;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
if( ZwCreateThreadEx(
&ThreadHandle,
0x1FFFFFui64,
&ObjectAttributes,
(VOID *)0xFFFFFFFFFFFFFFFFi64,
0i64,
0i64,
(UINT64)CallbackContext,
0i64,
0x1000ui64,
0x1000ui64,
0i64) < 0 )
{
PsTerminateProcess((ULONG_PTR)Process, 0xC0000725ui64);
}
else
{
Object = 0i64;
ObReferenceObjectByHandle(ThreadHandle, 0x1FFFFFui64, (_OBJECT_TYPE *)PsThreadType, 0, &Object, 0i64);
KeRequestTerminationProcess((_KTHREAD *)Object, 3i64);
ObCloseHandle(ThreadHandle, 0);
HalPutDmaAdapter((PADAPTER_OBJECT)Object);
}
}
}
else
{
KeRequestTerminationProcess((_KTHREAD *)CurrentThread, 2i64);
}
KeLeaveCriticalRegionThread((_KTHREAD *)CurrentThread);
return result;
}Referenced by:
MiKernelWriteToExecutableMemory