RtlpAllowsLowBoxAccess

bool __fastcall RtlpAllowsLowBoxAccess(_RTL_ATOM_TABLE_ENTRY *AtomEntry){
  WCHAR v1; 
  bool result; 
  bool v4; 
  bool v5; 
  UINT64 v6; 
  WCHAR *PoolWithTag; 
  WCHAR v8; 
  WCHAR *v9; 
  const WCHAR *v10; 
  bool v11; 
  UINT64 DesiredAccess; 
  UINT64 v13; 
  UINT8 EffectiveOnly[4]; 
  UINT64 GrantedAccess; 
  struct _UNICODE_STRING v16; 
  _SECURITY_IMPERSONATION_LEVEL ImpersonationLevel; 
  _TOKEN_TYPE TokenType; 
  PRIVILEGE_SET *Privileges; 
  struct _UNICODE_STRING DestinationString; 
  SECURITY_SUBJECT_CONTEXT SubjectSecurityContext; 
  INT64 v22[2]; 
  __int128 v23; 
  __int128 v24; 
  __int64 v25; 
  GENERIC_MAPPING GenericMapping; 
  char v27; 
  GrantedAccess = 0i64;
  result = 0;
  SubjectSecurityContext.ClientToken = 0i64;
  *(_QWORD *)&SubjectSecurityContext.ImpersonationLevel = 0i64;
  v4 = (AtomEntry->Reference.Flags & 2) == 0;
  EffectiveOnly[0] = 0;
  GenericMapping.GenericRead = 0x20000;
  GenericMapping.GenericWrite = 196608;
  GenericMapping.GenericExecute = 0x20000;
  GenericMapping.GenericAll = 2031616;
  *(_OWORD *)v22 = 0i64;
  v25 = 0i64;
  v23 = 0i64;
  v24 = 0i64;
  DestinationString = 0i64;
  v16 = 0i64;
  if( !v4 )
    return 1;
  if( byte_140C5424C )
  {
    RtlInitUnicodeString(&DestinationString, L"Global Atom Table Entry", v1);
    v5 = 1;
    v6 = 2i64 * AtomEntry->NameLength + 2;
    PoolWithTag = (WCHAR *)ExAllocatePoolWithTag(PagedPool, v6, 0x6D4E7441ui64);
    v9 = PoolWithTag;
    if( PoolWithTag )
    {
      memset((INT64)PoolWithTag, 0i64);
      if( RtlStringCbCopyW(v9, v6, AtomEntry->Name) < 0 )
        v10 = L"Unable to capture ATOM name.";
      else
        v10 = v9;
    }
    else
    {
      v10 = L"Unable to Allocate space for ATOM name.";
    }
    RtlInitUnicodeString(&v16, v10, v8);
    *(_QWORD *)&v23 = &DestinationString;
    *((_QWORD *)&v23 + 1) = &v16;
    SeSetLearningModeObjectInformation((INT64)v22);
    Privileges = (PRIVILEGE_SET *)&v27;
    SubjectSecurityContext.PrimaryToken = PsReferenceEffectiveToken(
                                            (_ETHREAD *)KeGetCurrentThread(),
                                            &TokenType,
                                            EffectiveOnly,
                                            &ImpersonationLevel,
                                            0i64);
    SubjectSecurityContext.ProcessAuditId = *(void **)(*((_QWORD *)KeGetCurrentThread() + 23) + 1088i64);
    LODWORD(v13) = 0;
    LODWORD(DesiredAccess) = 0x20000;
    v11 = SeAccessCheckWithHint(
            SeAtomSd,
            0i64,
            &SubjectSecurityContext,
            0i64,
            DesiredAccess,
            v13,
            &Privileges,
            &GenericMapping,
            *((_BYTE *)KeGetCurrentThread() + 562),
            &GrantedAccess,
            (INT64 *)((char *)&GrantedAccess + 4));
    ObfDereferenceObjectWithTag(SubjectSecurityContext.PrimaryToken, 0x746C6644ui64);
    if( v9 )
      ExFreePoolWithTag(v9, 0x6D4E7441u);
    SeClearLearningModeObjectInformation();
    if( !v11 || !(_DWORD)GrantedAccess )
      return 0;
    return v5;
  }
  return result;
}

Referenced by:

RtlpLookupLowBox