SeSubProcessToken
__int64 __fastcall SeSubProcessToken(
__int64 a1,
__int64 a2,
PADAPTER_OBJECT *a3,
char a4,
unsigned int a5,
__int64 a6,
unsigned int a7,
_DWORD *a8,
int a9,
__int64 a10,
_BYTE *a11){
_BYTE *v11;
int inserted;
PADAPTER_OBJECT v17;
PADAPTER_OBJECT v18;
PADAPTER_OBJECT *v19;
unsigned int DmaOperations;
unsigned int v22;
unsigned __int8 v23;
struct DMA_ADAPTER *v24;
unsigned __int8 *v25;
struct DMA_ADAPTER *v26;
int v27;
UINT64 ImpersonationLevel;
char v29;
unsigned __int8 Enforced[7];
PADAPTER_OBJECT DmaAdapter;
unsigned __int8 AuditOnly;
unsigned __int8 UnlessSecure;
char v34;
char v35;
char v36;
UINT8 EffectiveOnly[3];
_TOKEN_TYPE TokenType;
_SECURITY_IMPERSONATION_LEVEL v39;
_BYTE *v40;
_TOKEN *ExistingToken;
VOID *pNewIntegritySid;
PVOID OriginClaimData;
PADAPTER_OBJECT *v44;
_SECURITY_SUBJECT_CONTEXT v45;
_OBJECT_ATTRIBUTES ObjectAttributes;
INT64 result[4];
struct _SECURITY_SUBJECT_CONTEXT SubjectContext;
__int64 v49[28];
v11 = a11;
OriginClaimData = a8;
v44 = a3;
ExistingToken = (_TOKEN *)a2;
DmaAdapter = 0i64;
*((_DWORD *)&v45.ImpersonationLevel + 1) = 0;
v40 = a11;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
memset((INT64)result, 0i64);
memset((INT64)v49, 0i64);
*a3 = 0i64;
*(_WORD *)a11 = 0;
a11[2] = 0;
EffectiveOnly[0] = 0;
v39 = SecurityAnonymous;
TokenType = 0;
Enforced[0] = 0;
UnlessSecure = 0;
AuditOnly = 0;
v29 = 0;
v34 = 0;
v35 = 0;
v36 = 0;
pNewIntegritySid = 0i64;
SeTokenGetNoChildProcessRestricted((PACCESS_TOKEN)a2, Enforced, &UnlessSecure, &AuditOnly);
if( AuditOnly == 1 || Enforced[0] == 1 )
{
v22 = -1073740643;
if( (*(_DWORD *)a6 & 2) != 0 )
{
v24 = (struct DMA_ADAPTER *)PsReferenceEffectiveToken(
(_ETHREAD *)KeGetCurrentThread(),
&TokenType,
EffectiveOnly,
&v39,
0i64);
v26 = v24;
if( TokenType == TokenImpersonation && v39 < SecurityImpersonation
|| (v22 = SeTokenIsNoChildProcessRestrictionEnforced(v24, v25) ? 0xC000049D : 0, TokenType != TokenPrimary) )
{
if( v26 )
HalPutDmaAdapter(v26);
}
else
{
ObFastDereferenceObject((INT64 *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1208i64), v26);
}
}
inserted = 0;
if( *(_DWORD *)(a6 + 8) != 1 )
inserted = v22;
if( (*(_DWORD *)(a1 + 2172) & 1) != 0 )
inserted = *(_QWORD *)(a1 + 2240) != 0i64 ? inserted : 0;
if( inserted >= 0 )
goto LABEL_46;
if( UnlessSecure && *(_DWORD *)(a6 + 12) )
inserted = 0;
if( inserted >= 0 )
{
LABEL_46:
v11 = v40;
}
else
{
v23 = Enforced[0];
EtwTimLogProhibitChildProcessCreation(
(unsigned int)(Enforced[0] != 0) + 1,
*(_QWORD *)(a6 + 16),
(UNICODE_STRING *)((*(_QWORD *)(a6 + 24) + 96i64) & -(__int64)(*(_QWORD *)(a6 + 24) != 0i64)),
(UNICODE_STRING *)((*(_QWORD *)(a6 + 24) + 112i64) & -(__int64)(*(_QWORD *)(a6 + 24) != 0i64)));
if( v23 )
{
LABEL_22:
if( inserted >= 0 )
goto LABEL_23;
goto LABEL_61;
}
v11 = v40;
}
}
ObjectAttributes.Length = 48;
memset(&ObjectAttributes.RootDirectory, 0, 20);
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
inserted = SepDuplicateToken(
ExistingToken,
&ObjectAttributes,
0,
TokenPrimary,
SecurityAnonymous,
0,
1u,
(_TOKEN **)&DmaAdapter);
if( inserted < 0 )
{
LABEL_54:
DmaAdapter = 0i64;
goto LABEL_22;
}
v17 = DmaAdapter;
if( ((__int64)DmaAdapter[12].DmaOperations & 0x4000) != 0 )
{
DmaOperations = (unsigned int)DmaAdapter[7].DmaOperations;
if( DmaOperations != a5 )
{
SepDereferenceLowBoxNumberEntry(DmaOperations, DmaAdapter[67].DmaOperations);
DmaAdapter[67].DmaOperations = 0i64;
SepSetTokenSessionById((INT64)DmaAdapter, a5, 0, 0i64, 0i64);
LODWORD(DmaAdapter[7].DmaOperations) = a5;
v27 = SepSetTokenLowboxNumber((_TOKEN *)DmaAdapter, *(VOID **)&DmaAdapter[49].Version);
inserted = v27;
if( v27 < 0 )
goto LABEL_61;
v17 = DmaAdapter;
}
}
SepSetTokenSessionById((INT64)v17, a5, 0, 0i64, 0i64);
LODWORD(DmaAdapter[7].DmaOperations) = a5;
LODWORD(DmaAdapter[12].DmaOperations) &= ~0x200000u;
if( (*(_DWORD *)a6 & 1) != 0 )
{
LODWORD(DmaAdapter[12].DmaOperations) |= 0x80000u;
if( (*(_DWORD *)a6 & 4) != 0 )
LODWORD(DmaAdapter[12].DmaOperations) |= 0x100000u;
}
inserted = SepSetTokenBnoIsolation((INT64)DmaAdapter, 0, 0i64, 0i64, 0i64);
if( inserted < 0 )
goto LABEL_61;
inserted = SepDesktopAppxSubProcessToken(
(_DWORD)DmaAdapter,
a1,
*(_DWORD *)(a6 + 4),
(unsigned int)&v34,
(__int64)&v35);
if( inserted < 0 )
goto LABEL_61;
inserted = SepMandatorySubProcessToken(
(_TOKEN *)((unsigned __int64)ExistingToken & -(__int64)((a4 & 2) != 0)),
(_TOKEN *)DmaAdapter,
(_EPROCESS *)a1,
&pNewIntegritySid);
if( inserted < 0 )
goto LABEL_61;
inserted = SepSetTrustLevelForProcessToken((__int64)DmaAdapter, a1, &v29);
if( inserted < 0 )
goto LABEL_61;
if( (SepTokenSingletonAttributesConfig & 3) == 3 )
{
inserted = SepSetProcessUniqueAttribute(DmaAdapter);
if( inserted < 0 )
goto LABEL_61;
}
v18 = DmaAdapter;
if( ((__int64)DmaAdapter[12].DmaOperations & 0x4000) != 0 && (a7 & 1) != 0 )
{
inserted = SepSetTokenAllApplicationPackagesPolicy((_TOKEN *)DmaAdapter, a7);
if( inserted < 0 )
goto LABEL_61;
v18 = DmaAdapter;
}
if( OriginClaimData )
{
SepAddTokenOriginClaim(OriginClaimData, (unsigned int)a9, v18);
v18 = DmaAdapter;
}
if( !a10 )
{
LABEL_16:
if( (a4 & 2) == 0 || pNewIntegritySid )
v29 = 1;
if( v29 )
{
v45.PrimaryToken = v18;
v45.ClientToken = 0i64;
v45.ImpersonationLevel = SecurityAnonymous;
v45.ProcessAuditId = *(void **)(*((_QWORD *)KeGetCurrentThread() + 23) + 1088i64);
SepCreateAccessStateFromSubjectContext(&v45, (_ACCESS_STATE *)result, (_AUX_ACCESS_DATA *)v49, 0i64, 0i64);
}
else
{
SeCreateAccessState((_ACCESS_STATE *)result, (_AUX_ACCESS_DATA *)v49, 0i64, 0i64);
}
LODWORD(ImpersonationLevel) = 0;
v36 = 1;
inserted = ObInsertObjectEx(DmaAdapter, (ACCESS_STATE *)result, 0i64, 0i64, ImpersonationLevel, 0i64, 0i64);
if( inserted >= 0 )
{
SepAppendAceToTokenObjectAcl((_TOKEN *)DmaAdapter, 8ui64, SeAliasAdminsSid);
v19 = v44;
BYTE4(DmaAdapter[12].DmaOperations) = a4 & 1;
*v19 = DmaAdapter;
*v11 = v29;
v11[1] = v34;
v11[2] = v35;
goto LABEL_22;
}
goto LABEL_54;
}
inserted = SepSetTokenBnoIsolation(
(INT64)v18,
*(_BYTE *)(a10 + 32),
a10,
*(unsigned int *)(a10 + 16),
*(_QWORD *)(a10 + 24));
if( inserted >= 0 )
{
v18 = DmaAdapter;
goto LABEL_16;
}
LABEL_61:
if( DmaAdapter )
HalPutDmaAdapter(DmaAdapter);
LABEL_23:
if( v36 )
{
SepDeleteAccessState((ACCESS_STATE *)result);
if( !v29 )
SeReleaseSubjectContext(&SubjectContext);
}
return(unsigned int)inserted;
}Referenced by:
PspInitializeProcessSecurity