SeSubProcessToken

__int64 __fastcall SeSubProcessToken(
        __int64 a1,
        __int64 a2,
        PADAPTER_OBJECT *a3,
        char a4,
        unsigned int a5,
        __int64 a6,
        unsigned int a7,
        _DWORD *a8,
        int a9,
        __int64 a10,
        _BYTE *a11){
  _BYTE *v11; 
  int inserted; 
  PADAPTER_OBJECT v17; 
  PADAPTER_OBJECT v18; 
  PADAPTER_OBJECT *v19; 
  unsigned int DmaOperations; 
  unsigned int v22; 
  unsigned __int8 v23; 
  struct DMA_ADAPTER *v24; 
  unsigned __int8 *v25; 
  struct DMA_ADAPTER *v26; 
  int v27; 
  UINT64 ImpersonationLevel; 
  char v29; 
  unsigned __int8 Enforced[7]; 
  PADAPTER_OBJECT DmaAdapter; 
  unsigned __int8 AuditOnly; 
  unsigned __int8 UnlessSecure; 
  char v34; 
  char v35; 
  char v36; 
  UINT8 EffectiveOnly[3]; 
  _TOKEN_TYPE TokenType; 
  _SECURITY_IMPERSONATION_LEVEL v39; 
  _BYTE *v40; 
  _TOKEN *ExistingToken; 
  VOID *pNewIntegritySid; 
  PVOID OriginClaimData; 
  PADAPTER_OBJECT *v44; 
  _SECURITY_SUBJECT_CONTEXT v45; 
  _OBJECT_ATTRIBUTES ObjectAttributes; 
  INT64 result[4]; 
  struct _SECURITY_SUBJECT_CONTEXT SubjectContext; 
  __int64 v49[28]; 
  v11 = a11;
  OriginClaimData = a8;
  v44 = a3;
  ExistingToken = (_TOKEN *)a2;
  DmaAdapter = 0i64;
  *((_DWORD *)&v45.ImpersonationLevel + 1) = 0;
  v40 = a11;
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  memset((INT64)result, 0i64);
  memset((INT64)v49, 0i64);
  *a3 = 0i64;
  *(_WORD *)a11 = 0;
  a11[2] = 0;
  EffectiveOnly[0] = 0;
  v39 = SecurityAnonymous;
  TokenType = 0;
  Enforced[0] = 0;
  UnlessSecure = 0;
  AuditOnly = 0;
  v29 = 0;
  v34 = 0;
  v35 = 0;
  v36 = 0;
  pNewIntegritySid = 0i64;
  SeTokenGetNoChildProcessRestricted((PACCESS_TOKEN)a2, Enforced, &UnlessSecure, &AuditOnly);
  if( AuditOnly == 1 || Enforced[0] == 1 )
  {
    v22 = -1073740643;
    if( (*(_DWORD *)a6 & 2) != 0 )
    {
      v24 = (struct DMA_ADAPTER *)PsReferenceEffectiveToken(
                                    (_ETHREAD *)KeGetCurrentThread(),
                                    &TokenType,
                                    EffectiveOnly,
                                    &v39,
                                    0i64);
      v26 = v24;
      if( TokenType == TokenImpersonation && v39 < SecurityImpersonation
        || (v22 = SeTokenIsNoChildProcessRestrictionEnforced(v24, v25) ? 0xC000049D : 0, TokenType != TokenPrimary) )
      {
        if( v26 )
          HalPutDmaAdapter(v26);
      }
      else
      {
        ObFastDereferenceObject((INT64 *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1208i64), v26);
      }
    }
    inserted = 0;
    if( *(_DWORD *)(a6 + 8) != 1 )
      inserted = v22;
    if( (*(_DWORD *)(a1 + 2172) & 1) != 0 )
      inserted = *(_QWORD *)(a1 + 2240) != 0i64 ? inserted : 0;
    if( inserted >= 0 )
      goto LABEL_46;
    if( UnlessSecure && *(_DWORD *)(a6 + 12) )
      inserted = 0;
    if( inserted >= 0 )
    {
LABEL_46:
      v11 = v40;
    }
    else
    {
      v23 = Enforced[0];
      EtwTimLogProhibitChildProcessCreation(
        (unsigned int)(Enforced[0] != 0) + 1,
        *(_QWORD *)(a6 + 16),
        (UNICODE_STRING *)((*(_QWORD *)(a6 + 24) + 96i64) & -(__int64)(*(_QWORD *)(a6 + 24) != 0i64)),
        (UNICODE_STRING *)((*(_QWORD *)(a6 + 24) + 112i64) & -(__int64)(*(_QWORD *)(a6 + 24) != 0i64)));
      if( v23 )
      {
LABEL_22:
        if( inserted >= 0 )
          goto LABEL_23;
        goto LABEL_61;
      }
      v11 = v40;
    }
  }
  ObjectAttributes.Length = 48;
  memset(&ObjectAttributes.RootDirectory, 0, 20);
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  inserted = SepDuplicateToken(
               ExistingToken,
               &ObjectAttributes,
               0,
               TokenPrimary,
               SecurityAnonymous,
               0,
               1u,
               (_TOKEN **)&DmaAdapter);
  if( inserted < 0 )
  {
LABEL_54:
    DmaAdapter = 0i64;
    goto LABEL_22;
  }
  v17 = DmaAdapter;
  if( ((__int64)DmaAdapter[12].DmaOperations & 0x4000) != 0 )
  {
    DmaOperations = (unsigned int)DmaAdapter[7].DmaOperations;
    if( DmaOperations != a5 )
    {
      SepDereferenceLowBoxNumberEntry(DmaOperations, DmaAdapter[67].DmaOperations);
      DmaAdapter[67].DmaOperations = 0i64;
      SepSetTokenSessionById((INT64)DmaAdapter, a5, 0, 0i64, 0i64);
      LODWORD(DmaAdapter[7].DmaOperations) = a5;
      v27 = SepSetTokenLowboxNumber((_TOKEN *)DmaAdapter, *(VOID **)&DmaAdapter[49].Version);
      inserted = v27;
      if( v27 < 0 )
        goto LABEL_61;
      v17 = DmaAdapter;
    }
  }
  SepSetTokenSessionById((INT64)v17, a5, 0, 0i64, 0i64);
  LODWORD(DmaAdapter[7].DmaOperations) = a5;
  LODWORD(DmaAdapter[12].DmaOperations) &= ~0x200000u;
  if( (*(_DWORD *)a6 & 1) != 0 )
  {
    LODWORD(DmaAdapter[12].DmaOperations) |= 0x80000u;
    if( (*(_DWORD *)a6 & 4) != 0 )
      LODWORD(DmaAdapter[12].DmaOperations) |= 0x100000u;
  }
  inserted = SepSetTokenBnoIsolation((INT64)DmaAdapter, 0, 0i64, 0i64, 0i64);
  if( inserted < 0 )
    goto LABEL_61;
  inserted = SepDesktopAppxSubProcessToken(
               (_DWORD)DmaAdapter,
               a1,
               *(_DWORD *)(a6 + 4),
               (unsigned int)&v34,
               (__int64)&v35);
  if( inserted < 0 )
    goto LABEL_61;
  inserted = SepMandatorySubProcessToken(
               (_TOKEN *)((unsigned __int64)ExistingToken & -(__int64)((a4 & 2) != 0)),
               (_TOKEN *)DmaAdapter,
               (_EPROCESS *)a1,
               &pNewIntegritySid);
  if( inserted < 0 )
    goto LABEL_61;
  inserted = SepSetTrustLevelForProcessToken((__int64)DmaAdapter, a1, &v29);
  if( inserted < 0 )
    goto LABEL_61;
  if( (SepTokenSingletonAttributesConfig & 3) == 3 )
  {
    inserted = SepSetProcessUniqueAttribute(DmaAdapter);
    if( inserted < 0 )
      goto LABEL_61;
  }
  v18 = DmaAdapter;
  if( ((__int64)DmaAdapter[12].DmaOperations & 0x4000) != 0 && (a7 & 1) != 0 )
  {
    inserted = SepSetTokenAllApplicationPackagesPolicy((_TOKEN *)DmaAdapter, a7);
    if( inserted < 0 )
      goto LABEL_61;
    v18 = DmaAdapter;
  }
  if( OriginClaimData )
  {
    SepAddTokenOriginClaim(OriginClaimData, (unsigned int)a9, v18);
    v18 = DmaAdapter;
  }
  if( !a10 )
  {
LABEL_16:
    if( (a4 & 2) == 0 || pNewIntegritySid )
      v29 = 1;
    if( v29 )
    {
      v45.PrimaryToken = v18;
      v45.ClientToken = 0i64;
      v45.ImpersonationLevel = SecurityAnonymous;
      v45.ProcessAuditId = *(void **)(*((_QWORD *)KeGetCurrentThread() + 23) + 1088i64);
      SepCreateAccessStateFromSubjectContext(&v45, (_ACCESS_STATE *)result, (_AUX_ACCESS_DATA *)v49, 0i64, 0i64);
    }
    else
    {
      SeCreateAccessState((_ACCESS_STATE *)result, (_AUX_ACCESS_DATA *)v49, 0i64, 0i64);
    }
    LODWORD(ImpersonationLevel) = 0;
    v36 = 1;
    inserted = ObInsertObjectEx(DmaAdapter, (ACCESS_STATE *)result, 0i64, 0i64, ImpersonationLevel, 0i64, 0i64);
    if( inserted >= 0 )
    {
      SepAppendAceToTokenObjectAcl((_TOKEN *)DmaAdapter, 8ui64, SeAliasAdminsSid);
      v19 = v44;
      BYTE4(DmaAdapter[12].DmaOperations) = a4 & 1;
      *v19 = DmaAdapter;
      *v11 = v29;
      v11[1] = v34;
      v11[2] = v35;
      goto LABEL_22;
    }
    goto LABEL_54;
  }
  inserted = SepSetTokenBnoIsolation(
               (INT64)v18,
               *(_BYTE *)(a10 + 32),
               a10,
               *(unsigned int *)(a10 + 16),
               *(_QWORD *)(a10 + 24));
  if( inserted >= 0 )
  {
    v18 = DmaAdapter;
    goto LABEL_16;
  }
LABEL_61:
  if( DmaAdapter )
    HalPutDmaAdapter(DmaAdapter);
LABEL_23:
  if( v36 )
  {
    SepDeleteAccessState((ACCESS_STATE *)result);
    if( !v29 )
      SeReleaseSubjectContext(&SubjectContext);
  }
  return(unsigned int)inserted;
}

Referenced by:

PspInitializeProcessSecurity