RtlpAllowsLowBoxAccess
bool __fastcall RtlpAllowsLowBoxAccess(_RTL_ATOM_TABLE_ENTRY *AtomEntry){
WCHAR v1;
bool result;
bool v4;
bool v5;
UINT64 v6;
WCHAR *PoolWithTag;
WCHAR v8;
WCHAR *v9;
const WCHAR *v10;
bool v11;
UINT64 DesiredAccess;
UINT64 v13;
UINT8 EffectiveOnly[4];
UINT64 GrantedAccess;
struct _UNICODE_STRING v16;
_SECURITY_IMPERSONATION_LEVEL ImpersonationLevel;
_TOKEN_TYPE TokenType;
PRIVILEGE_SET *Privileges;
struct _UNICODE_STRING DestinationString;
SECURITY_SUBJECT_CONTEXT SubjectSecurityContext;
INT64 v22[2];
__int128 v23;
__int128 v24;
__int64 v25;
GENERIC_MAPPING GenericMapping;
char v27;
GrantedAccess = 0i64;
result = 0;
SubjectSecurityContext.ClientToken = 0i64;
*(_QWORD *)&SubjectSecurityContext.ImpersonationLevel = 0i64;
v4 = (AtomEntry->Reference.Flags & 2) == 0;
EffectiveOnly[0] = 0;
GenericMapping.GenericRead = 0x20000;
GenericMapping.GenericWrite = 196608;
GenericMapping.GenericExecute = 0x20000;
GenericMapping.GenericAll = 2031616;
*(_OWORD *)v22 = 0i64;
v25 = 0i64;
v23 = 0i64;
v24 = 0i64;
DestinationString = 0i64;
v16 = 0i64;
if( !v4 )
return 1;
if( byte_140C5424C )
{
RtlInitUnicodeString(&DestinationString, L"Global Atom Table Entry", v1);
v5 = 1;
v6 = 2i64 * AtomEntry->NameLength + 2;
PoolWithTag = (WCHAR *)ExAllocatePoolWithTag(PagedPool, v6, 0x6D4E7441ui64);
v9 = PoolWithTag;
if( PoolWithTag )
{
memset((INT64)PoolWithTag, 0i64);
if( RtlStringCbCopyW(v9, v6, AtomEntry->Name) < 0 )
v10 = L"Unable to capture ATOM name.";
else
v10 = v9;
}
else
{
v10 = L"Unable to Allocate space for ATOM name.";
}
RtlInitUnicodeString(&v16, v10, v8);
*(_QWORD *)&v23 = &DestinationString;
*((_QWORD *)&v23 + 1) = &v16;
SeSetLearningModeObjectInformation((INT64)v22);
Privileges = (PRIVILEGE_SET *)&v27;
SubjectSecurityContext.PrimaryToken = PsReferenceEffectiveToken(
(_ETHREAD *)KeGetCurrentThread(),
&TokenType,
EffectiveOnly,
&ImpersonationLevel,
0i64);
SubjectSecurityContext.ProcessAuditId = *(void **)(*((_QWORD *)KeGetCurrentThread() + 23) + 1088i64);
LODWORD(v13) = 0;
LODWORD(DesiredAccess) = 0x20000;
v11 = SeAccessCheckWithHint(
SeAtomSd,
0i64,
&SubjectSecurityContext,
0i64,
DesiredAccess,
v13,
&Privileges,
&GenericMapping,
*((_BYTE *)KeGetCurrentThread() + 562),
&GrantedAccess,
(INT64 *)((char *)&GrantedAccess + 4));
ObfDereferenceObjectWithTag(SubjectSecurityContext.PrimaryToken, 0x746C6644ui64);
if( v9 )
ExFreePoolWithTag(v9, 0x6D4E7441u);
SeClearLearningModeObjectInformation();
if( !v11 || !(_DWORD)GrantedAccess )
return 0;
return v5;
}
return result;
}Referenced by:
RtlpLookupLowBox