SepCheckAndCopySelfRelativeSD
NTSTATUS __stdcall SepCheckAndCopySelfRelativeSD(
SECURITY_DESCRIPTOR *SecurityDescriptorIn,
SECURITY_DESCRIPTOR **SecurityDescriptorOut,
UINT64 *SDLength,
UINT8 *NeedToFree){
NTSTATUS v7;
SECURITY_DESCRIPTOR *PoolWithTag;
SECURITY_DESCRIPTOR *v9;
PSECURITY_DESCRIPTOR AbsoluteSecurityDescriptor;
AbsoluteSecurityDescriptor = SecurityDescriptorIn;
*SecurityDescriptorOut = 0i64;
*(_DWORD *)SDLength = 0;
*NeedToFree = 0;
v7 = 0;
if( SecurityDescriptorIn )
{
if( (SecurityDescriptorIn->Control & 0x8000u) != 0 )
{
*(_DWORD *)SDLength = SepSecurityDescriptorStrictLength(SecurityDescriptorIn);
*SecurityDescriptorOut = v9;
}
else
{
v7 = RtlAbsoluteToSelfRelativeSD(&AbsoluteSecurityDescriptor, 0i64, SDLength);
if( v7 == -1073741789 )
{
PoolWithTag = (SECURITY_DESCRIPTOR *)ExAllocatePoolWithTag(PagedPool, *(unsigned int *)SDLength, 0x70416553ui64);
*SecurityDescriptorOut = PoolWithTag;
if( PoolWithTag )
{
v7 = RtlAbsoluteToSelfRelativeSD(AbsoluteSecurityDescriptor, PoolWithTag, SDLength);
if( v7 >= 0 )
{
*NeedToFree = 1;
}
else
{
ExFreePoolWithTag(*SecurityDescriptorOut, 0);
*SecurityDescriptorOut = 0i64;
}
}
else
{
return -1073741670;
}
}
}
}
return v7;
}Referenced by:
SeOperationAuditAlarm
SepAdtOpenObjectAuditAlarm
SepAdtStagingEvent