CmUpdateFeatureConfiguration

INT64 __stdcall CmUpdateFeatureConfiguration(PVOID Src, size_t Size, KPROCESSOR_MODE AccessMode){
  UINT64 v4; 
  UINT8 *v6; 
  bool v7; 
  INT64 v8; 
  unsigned int updated; 
  UINT8 *TransientPoolWithQuotaTag; 
  unsigned __int64 v11; 
  INT64 v12; 
  UINT64 a5; 
  UINT64 a5a; 
  int GrantedAccess[3]; 
  UINT8 *v17; 
  struct _SECURITY_SUBJECT_CONTEXT SubjectSecurityContext; 
  INT64 AccessStatus; 
  v4 = (unsigned int)Size;
  LODWORD(AccessStatus) = 0;
  GrantedAccess[0] = 0;
  memset(&SubjectSecurityContext, 0, sizeof(SubjectSecurityContext));
  v6 = 0i64;
  SeCaptureSubjectContext(&SubjectSecurityContext);
  LODWORD(a5) = 0;
  v7 = SeAccessCheck(
         CmFcFeatureConfigSecurityDescriptor,
         &SubjectSecurityContext,
         0,
         1ui64,
         a5,
         0i64,
         &CmFcFeatureConfigMapping,
         AccessMode,
         (UINT64 *)GrantedAccess,
         &AccessStatus);
  SeReleaseSubjectContext(&SubjectSecurityContext);
  if( !v7 )
  {
    updated = AccessStatus;
    goto LABEL_13;
  }
  if( (unsigned int)v4 < 0x10 )
    goto LABEL_4;
  TransientPoolWithQuotaTag = (UINT8 *)CmpAllocateTransientPoolWithQuotaTag(v8, v4, 0x63466D43ui64);
  v6 = TransientPoolWithQuotaTag;
  v17 = TransientPoolWithQuotaTag;
  if( TransientPoolWithQuotaTag )
  {
    memmove(TransientPoolWithQuotaTag, (UINT8 *)Src, v4);
    v11 = 32i64 * *((unsigned int *)v6 + 3);
    if( v11 > 0xFFFFFFFF )
      goto LABEL_12;
    v12 = (unsigned int)(v11 + 16);
    if( (unsigned int)v12 < (unsigned int)v11 )
      goto LABEL_12;
    if( (_DWORD)v12 != (_DWORD)v4 )
    {
LABEL_4:
      updated = -1073741820;
      goto LABEL_13;
    }
    if( *((_DWORD *)v6 + 2) == 1 )
    {
      LODWORD(a5a) = *((_DWORD *)v6 + 3);
      updated = CmFcManagerUpdateFeatureConfigurations(v12, *(_QWORD *)v6, 1i64, (_DWORD *)v6 + 4, a5a);
    }
    else
    {
LABEL_12:
      updated = -1073741811;
    }
  }
  else
  {
    updated = -1073741670;
  }
LABEL_13:
  if( v6 )
    CmSiFreeMemory((PPRIVILEGE_SET)v6);
  return updated;
}

Referenced by:

NtSetSystemInformation