AuthzBasepGetOperandStringCaseForEvaluation
INT64 __fastcall AuthzBasepGetOperandStringCaseForEvaluation(INT64 a1, CHAR *a2){
CHAR v2;
__int64 v3;
unsigned __int8 CurrentIrql;
v2 = 1;
if( *(_DWORD *)(a1 + 12) == 1 )
{
v3 = *(_QWORD *)(a1 + 56);
LABEL_3:
v2 = *(_BYTE *)(v3 + 36) & 2;
goto LABEL_4;
}
v3 = *(_QWORD *)(a1 + 16);
if( *(_DWORD *)(a1 + 52) == 1 )
goto LABEL_3;
if( (*(_DWORD *)(v3 + 36) & 2) == 0 && (*(_DWORD *)(*(_QWORD *)(a1 + 56) + 36i64) & 2) == 0 )
v2 = 0;
LABEL_4:
*a2 = v2;
CurrentIrql = KeGetCurrentIrql();
if( v2 || CurrentIrql < 2u )
return 0i64;
else
return 3221225659i64;
}Referenced by:
AuthzBasepCompareFQBNOperands
AuthzBasepCompareUnicodeStringOperands