CmUpdateFeatureConfiguration
INT64 __stdcall CmUpdateFeatureConfiguration(PVOID Src, size_t Size, KPROCESSOR_MODE AccessMode){
UINT64 v4;
UINT8 *v6;
bool v7;
INT64 v8;
unsigned int updated;
UINT8 *TransientPoolWithQuotaTag;
unsigned __int64 v11;
INT64 v12;
UINT64 a5;
UINT64 a5a;
int GrantedAccess[3];
UINT8 *v17;
struct _SECURITY_SUBJECT_CONTEXT SubjectSecurityContext;
INT64 AccessStatus;
v4 = (unsigned int)Size;
LODWORD(AccessStatus) = 0;
GrantedAccess[0] = 0;
memset(&SubjectSecurityContext, 0, sizeof(SubjectSecurityContext));
v6 = 0i64;
SeCaptureSubjectContext(&SubjectSecurityContext);
LODWORD(a5) = 0;
v7 = SeAccessCheck(
CmFcFeatureConfigSecurityDescriptor,
&SubjectSecurityContext,
0,
1ui64,
a5,
0i64,
&CmFcFeatureConfigMapping,
AccessMode,
(UINT64 *)GrantedAccess,
&AccessStatus);
SeReleaseSubjectContext(&SubjectSecurityContext);
if( !v7 )
{
updated = AccessStatus;
goto LABEL_13;
}
if( (unsigned int)v4 < 0x10 )
goto LABEL_4;
TransientPoolWithQuotaTag = (UINT8 *)CmpAllocateTransientPoolWithQuotaTag(v8, v4, 0x63466D43ui64);
v6 = TransientPoolWithQuotaTag;
v17 = TransientPoolWithQuotaTag;
if( TransientPoolWithQuotaTag )
{
memmove(TransientPoolWithQuotaTag, (UINT8 *)Src, v4);
v11 = 32i64 * *((unsigned int *)v6 + 3);
if( v11 > 0xFFFFFFFF )
goto LABEL_12;
v12 = (unsigned int)(v11 + 16);
if( (unsigned int)v12 < (unsigned int)v11 )
goto LABEL_12;
if( (_DWORD)v12 != (_DWORD)v4 )
{
LABEL_4:
updated = -1073741820;
goto LABEL_13;
}
if( *((_DWORD *)v6 + 2) == 1 )
{
LODWORD(a5a) = *((_DWORD *)v6 + 3);
updated = CmFcManagerUpdateFeatureConfigurations(v12, *(_QWORD *)v6, 1i64, (_DWORD *)v6 + 4, a5a);
}
else
{
LABEL_12:
updated = -1073741811;
}
}
else
{
updated = -1073741670;
}
LABEL_13:
if( v6 )
CmSiFreeMemory((PPRIVILEGE_SET)v6);
return updated;
}Referenced by:
NtSetSystemInformation