KiSystemCall64Shadow
VOID __stdcall KiSystemCall64Shadow(INT64 a1, UINT64 a2){
unsigned __int64 v2;
unsigned __int64 v3;
unsigned __int64 v4;
unsigned __int64 v5;
__int64 v6;
unsigned __int64 v8;
_KTRAP_FRAME *__shifted(_KTRAP_FRAME,0x80) TrapFrame;
unsigned __int8 BpbKernelSpecCtrl;
unsigned __int8 BpbState;
_QWORD v12[50];
__swapgs();
__writegsqword(0x9010u, (unsigned __int64)v12);
if( !_bittest(MK_FP(__GS__, 36888i64), 1u) )
__writecr3((unsigned __int64)v12);
v12[49] = 43i64;
v12[48] = KeGetPcr()->Prcb.UserRspShadow;
v12[47] = v6;
v12[46] = 51i64;
v12[45] = a1;
TrapFrame = KeGetTrapFrame();
ADJ(TrapFrame)->_Rbx = v2;
ADJ(TrapFrame)->_Rdi = v3;
ADJ(TrapFrame)->_Rsi = v4;
if( (_BYTE)KeSmapEnabled && (ADJ(TrapFrame)->SegCs & 1) != 0 )
__stac();
ADJ(TrapFrame)->_Rax = v8;
ADJ(TrapFrame)->_Rcx = v5;
ADJ(TrapFrame)->_Rdx = a2;
__writegsqword(0x270u, KeGetCurrentThread()->Process->SecurityDomain);
__writegsbyte(0x851u, KeGetPcr()->Prcb.BpbRetpolineExitSpecCtrl);
__writegsbyte(0x852u, KeGetPcr()->Prcb.BpbState);
BpbKernelSpecCtrl = KeGetPcr()->Prcb.BpbKernelSpecCtrl;
if( KeGetPcr()->Prcb.BpbCurrentSpecCtrl != BpbKernelSpecCtrl )
{
__writegsbyte(0x27Au, BpbKernelSpecCtrl);
__writemsr(0x48u, BpbKernelSpecCtrl);
}
BpbState = KeGetPcr()->Prcb.BpbState;
if( (BpbState & 8) != 0 )
{
__writemsr(0x49u, 1ui64);
BpbState = KeGetPcr()->Prcb.BpbState;
}
if( (BpbState & 2) != 0 )
__flush_rsb();
_mm_lfence();
__writegsbyte(0x853u, 0);
JUMPOUT(0x14040D63Ai64);
}Referenced by:
No references.