SeCaptureUnicodeStringStructures
NTSTATUS __stdcall SeCaptureUnicodeStringStructures(
_UNICODE_STRING *pAttributes,
UINT64 AttributeCount,
INT8 RequestorMode,
_UNICODE_STRING **ppCapturedAttributes){
unsigned int v5;
unsigned int v7;
UINT64 v8;
NTSTATUS v9;
VOID **PoolWithTag;
v5 = AttributeCount;
v7 = 0;
*ppCapturedAttributes = 0i64;
if( !pAttributes )
{
if( !(_DWORD)AttributeCount )
return 0;
return -1073741811;
}
if( !(_DWORD)AttributeCount )
return -1073741811;
if( !RequestorMode )
{
*ppCapturedAttributes = pAttributes;
return 0;
}
v8 = 16i64 * (unsigned int)AttributeCount;
if( is_mul_ok(0x10ui64, (unsigned int)AttributeCount) )
{
v9 = 0;
}
else
{
v8 = -1i64;
v9 = -1073741675;
}
if( v9 >= 0 )
{
PoolWithTag = ExAllocatePoolWithTag(1ui64, v8, 1934976339i64);
if( PoolWithTag )
{
if( v8 )
{
if( ((unsigned __int8)pAttributes & 3) != 0 )
ExRaiseDatatypeMisalignment();
if( (unsigned __int64)pAttributes + v8 > 0x7FFFFFFF0000i64
|| (_UNICODE_STRING *)((char *)pAttributes + v8) < pAttributes )
{
MEMORY[0x7FFFFFFF0000] = 0;
}
}
while( v7 < v5 )
{
*(_UNICODE_STRING *)&PoolWithTag[2 * v7] = pAttributes[v7];
++v7;
}
*ppCapturedAttributes = (_UNICODE_STRING *)PoolWithTag;
}
else
{
return -1073741670;
}
}
return v9;
}Referenced by:
SepCaptureUnicodeStringArray