SeCaptureUnicodeStringStructures

NTSTATUS __stdcall SeCaptureUnicodeStringStructures(
        _UNICODE_STRING *pAttributes,
        UINT64 AttributeCount,
        INT8 RequestorMode,
        _UNICODE_STRING **ppCapturedAttributes){
  unsigned int v5; 
  unsigned int v7; 
  UINT64 v8; 
  NTSTATUS v9; 
  VOID **PoolWithTag; 

  v5 = AttributeCount;
  v7 = 0;
  *ppCapturedAttributes = 0i64;
  if( !pAttributes )
  {
    if( !(_DWORD)AttributeCount )
      return 0;
    return -1073741811;
  }
  if( !(_DWORD)AttributeCount )
    return -1073741811;
  if( !RequestorMode )
  {
    *ppCapturedAttributes = pAttributes;
    return 0;
  }
  v8 = 16i64 * (unsigned int)AttributeCount;
  if( is_mul_ok(0x10ui64, (unsigned int)AttributeCount) )
  {
    v9 = 0;
  }
  else
  {
    v8 = -1i64;
    v9 = -1073741675;
  }
  if( v9 >= 0 )
  {
    PoolWithTag = ExAllocatePoolWithTag(1ui64, v8, 1934976339i64);
    if( PoolWithTag )
    {
      if( v8 )
      {
        if( ((unsigned __int8)pAttributes & 3) != 0 )
          ExRaiseDatatypeMisalignment();
        if( (unsigned __int64)pAttributes + v8 > 0x7FFFFFFF0000i64
          || (_UNICODE_STRING *)((char *)pAttributes + v8) < pAttributes )
        {
          MEMORY[0x7FFFFFFF0000] = 0;
        }
      }
      while( v7 < v5 )
      {
        *(_UNICODE_STRING *)&PoolWithTag[2 * v7] = pAttributes[v7];
        ++v7;
      }
      *ppCapturedAttributes = (_UNICODE_STRING *)PoolWithTag;
    }
    else
    {
      return -1073741670;
    }
  }
  return v9;
}

Referenced by:

SepCaptureUnicodeStringArray