AuthzBasepAllocateSecurityAttribute

UNICODE_STRING *__fastcall AuthzBasepAllocateSecurityAttribute(UNICODE_STRING *pAttributeName, UINT8 a2){
  UINT64 v3; 
  _POOL_TYPE v4; 
  UNICODE_STRING *result; 
  UNICODE_STRING *v6; 
  unsigned int Length; 
  wchar_t *Buffer; 
  unsigned __int64 v9; 
  v3 = pAttributeName->Length + 112i64;
  v4 = PagedPool;
  if( KeGetCurrentIrql() >= 2u )
    v4 = NonPagedPoolNx;
  result = (UNICODE_STRING *)ExAllocatePoolWithTag(v4, v3, 0x74416553ui64);
  v6 = result;
  if( result )
  {
    memset((INT64)result, 0i64);
    v6[2].MaximumLength = pAttributeName->Length;
    v6[2].Buffer = &v6[7].Length;
    Length = pAttributeName->Length;
    Buffer = pAttributeName->Buffer;
    if( (unsigned __int16)Length > v6[2].MaximumLength )
      Length = v6[2].MaximumLength;
    v6[2].Length = Length;
    v9 = Length;
    memmove((UINT8 *)&v6[7], (UINT8 *)Buffer, Length);
    if( (unsigned __int64)v6[2].Length + 2 <= v6[2].MaximumLength )
      *(&v6[7].Length + (v9 >> 1)) = 0;
    *(_QWORD *)&v6[5].Length = (char *)v6 + 72;
    v6[4].Buffer = (wchar_t *)&v6[4].Buffer;
    v6[6].Buffer = &v6[6].Length;
    *(_QWORD *)&v6[6].Length = v6 + 6;
    return v6;
  }
  return result;
}

Referenced by:

AuthzBasepAddSecurityAttribute
AuthzBasepDuplicateSecurityAttributes