PnpGetPropertiesSecurityDescriptor
VOID **PnpGetPropertiesSecurityDescriptor(){
VOID **v0;
_DWORD *v1;
unsigned int v2;
VOID **PoolWithTag;
UINT64 v4;
_ACL *v5;
unsigned int v6;
size_t v7;
VOID **v8;
VOID **v9;
_SID_IDENTIFIER_AUTHORITY IdentifierAuthority;
__int128 SecurityDescriptor[2];
__int64 v13;
char Sid[16];
*(_WORD *)&IdentifierAuthority.Value[4] = 1280;
v0 = 0i64;
v13 = 0i64;
*(_DWORD *)IdentifierAuthority.Value = 0;
memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
if( RtlInitializeSid(Sid, &IdentifierAuthority, 1u) >= 0 )
{
LODWORD(v1) = RtlSubAuthoritySid((INT64)Sid, 0i64);
*v1 = 18;
if( RtlValidSid(Sid) )
{
v2 = RtlLengthSid((INT64)Sid) + 16;
PoolWithTag = ExAllocatePoolWithTag(1ui64, v2, 1380994640i64);
v5 = (_ACL *)PoolWithTag;
if( PoolWithTag )
{
if( RtlCreateAcl((PACL)PoolWithTag, (_ACL)v2, 2ui64, v4) >= 0
&& RtlpAddKnownAce(v5, 2ui64, 2ui64, 0xF003Fui64, Sid, 0) >= 0
&& RtlCreateSecurityDescriptor(SecurityDescriptor, 1ui64) >= 0
&& RtlSetDaclSecurityDescriptor(SecurityDescriptor, 1u, v5, 0) >= 0
&& RtlSetOwnerSecurityDescriptor(SecurityDescriptor, Sid, 1u) >= 0
&& RtlSetGroupSecurityDescriptor(SecurityDescriptor, Sid, 1u) >= 0 )
{
WORD1(SecurityDescriptor[0]) |= 0x1400u;
if( RtlValidSecurityDescriptor(SecurityDescriptor) )
{
v6 = RtlLengthSecurityDescriptor((INT64)SecurityDescriptor);
*(_DWORD *)IdentifierAuthority.Value = v6;
if( v6 >= 0x28 )
{
v7 = v6;
v8 = ExAllocatePoolWithTag(1ui64, v6, 1380994640i64);
v9 = v8;
if( v8 )
{
memset(v8, 0i64, v7);
if( RtlAbsoluteToSelfRelativeSD(SecurityDescriptor, v9, (UINT64 *)IdentifierAuthority.Value) >= 0 )
{
v0 = v9;
v9 = 0i64;
}
if( v9 )
ExFreePoolWithTag(v9, 0);
}
}
}
}
ExFreePoolWithTag(v5, 0);
}
}
}
return v0;
}Referenced by:
PnpOpenPropertiesKey