AuthzBasepAllocateSecurityAttribute
UNICODE_STRING *__fastcall AuthzBasepAllocateSecurityAttribute(UNICODE_STRING *pAttributeName, UINT8 a2){
UINT64 v3;
_POOL_TYPE v4;
UNICODE_STRING *result;
UNICODE_STRING *v6;
unsigned int Length;
wchar_t *Buffer;
unsigned __int64 v9;
v3 = pAttributeName->Length + 112i64;
v4 = PagedPool;
if( KeGetCurrentIrql() >= 2u )
v4 = NonPagedPoolNx;
result = (UNICODE_STRING *)ExAllocatePoolWithTag(v4, v3, 0x74416553ui64);
v6 = result;
if( result )
{
memset((INT64)result, 0i64);
v6[2].MaximumLength = pAttributeName->Length;
v6[2].Buffer = &v6[7].Length;
Length = pAttributeName->Length;
Buffer = pAttributeName->Buffer;
if( (unsigned __int16)Length > v6[2].MaximumLength )
Length = v6[2].MaximumLength;
v6[2].Length = Length;
v9 = Length;
memmove((UINT8 *)&v6[7], (UINT8 *)Buffer, Length);
if( (unsigned __int64)v6[2].Length + 2 <= v6[2].MaximumLength )
*(&v6[7].Length + (v9 >> 1)) = 0;
*(_QWORD *)&v6[5].Length = (char *)v6 + 72;
v6[4].Buffer = (wchar_t *)&v6[4].Buffer;
v6[6].Buffer = &v6[6].Length;
*(_QWORD *)&v6[6].Length = v6 + 6;
return v6;
}
return result;
}Referenced by:
AuthzBasepAddSecurityAttribute
AuthzBasepDuplicateSecurityAttributes