ExpGetSystemPlatformBinary

INT64 __fastcall ExpGetSystemPlatformBinary(VOID *SystemInformation, UINT64 SystemInformationLength, CHAR PreviousMode){
  void *v4; 
  char v5; 
  _ETHREAD *CurrentThread; 
  NTSTATUS SystemFirmwareTableInformation; 
  NTSTATUS v8; 
  unsigned int v10; 
  _DWORD *PoolWithTag; 
  _ETHREAD *v12; 
  UINT64 v13; 
  unsigned __int16 *v14; 
  unsigned int v15; 
  _LARGE_INTEGER v16; 
  UINT64 v17; 
  UINT8 *v18; 
  UINT8 *v19; 
  unsigned __int16 v20; 
  unsigned int Length; 
  unsigned int Length_4; 
  UINT64 v24; 
  _DWORD *v25; 
  volatile void *Address; 
  UINT8 *dst; 
  PVOID BaseAddress; 
  SIZE_T NumberOfBytes; 
  __int128 SystemInformationa; 
  int v31; 
  dst = 0i64;
  LODWORD(v24) = 0;
  SystemInformationa = 0i64;
  v31 = 0;
  Address = 0i64;
  Length_4 = 0;
  v4 = 0i64;
  v25 = 0i64;
  v5 = 0;
  BaseAddress = 0i64;
  NumberOfBytes = 0i64;
  if( (unsigned int)SystemInformationLength < 0x20 )
  {
    v8 = -1073741811;
    goto LABEL_11;
  }
  LODWORD(v24) = *((_DWORD *)SystemInformation + 7);
  Length = *((_DWORD *)SystemInformation + 6);
  Address = (volatile void *)*((_QWORD *)SystemInformation + 1);
  dst = (UINT8 *)*((_QWORD *)SystemInformation + 2);
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  ExAcquirePushLockSharedEx((UINT64)&ExpPlatformBinaryLock, 0i64);
  v5 = 1;
  if( ExpPlatformBinaryTableInformation == (PVOID)-1i64 )
  {
    v8 = -1073741637;
    goto LABEL_11;
  }
  if( !ExpPlatformBinaryTableInformation )
  {
    if( _InterlockedCompareExchange64((volatile signed __int64 *)&ExpPlatformBinaryLock, 0i64, 17i64) != 17 )
      ExfReleasePushLockShared((INT64 *)&ExpPlatformBinaryLock);
    KeAbPostRelease(&ExpPlatformBinaryLock);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
    v5 = 0;
    if( Length || (_DWORD)v24 )
    {
      v8 = -1073741811;
      goto LABEL_11;
    }
    *(_QWORD *)&SystemInformationa = 0x141435049i64;
    *((_QWORD *)&SystemInformationa + 1) = 1413632087i64;
    SystemFirmwareTableInformation = ExpGetSystemFirmwareTableInformation(
                                       &SystemInformationa,
                                       0,
                                       0x14ui64,
                                       (UINT64 *)&Length_4);
    if( SystemFirmwareTableInformation != -1073741789 )
    {
      v8 = -1073741637;
      if( SystemFirmwareTableInformation >= 0 )
        v8 = -1073741701;
      goto LABEL_11;
    }
    v10 = Length_4;
    PoolWithTag = ExAllocatePoolWithTag(NonPagedPoolNx, Length_4, 0x54425057ui64);
    v4 = PoolWithTag;
    v25 = PoolWithTag;
    if( !PoolWithTag )
    {
      v8 = -1073741670;
      goto LABEL_11;
    }
    *PoolWithTag = 1094930505;
    PoolWithTag[1] = 1;
    PoolWithTag[2] = 1413632087;
    PoolWithTag[3] = v10 - 16;
    v8 = ExpGetSystemFirmwareTableInformation(PoolWithTag, 0, v10, (UINT64 *)&Length_4);
    if( v8 < 0 )
      goto LABEL_11;
    v12 = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)v12 + 242);
    ExAcquirePushLockExclusiveEx((UINT64)&ExpPlatformBinaryLock, 0i64);
    if( ExpPlatformBinaryTableInformation )
    {
      if( ExpPlatformBinaryTableInformation == (PVOID)-1i64 )
      {
        if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&ExpPlatformBinaryLock, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
          ExfTryToWakePushLock((volatile INT64 *)&ExpPlatformBinaryLock);
        KeAbPostRelease(&ExpPlatformBinaryLock);
        KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
        v8 = -1073741637;
        goto LABEL_11;
      }
    }
    else
    {
      ExpPlatformBinaryTableInformation = v4;
      v4 = 0i64;
      v25 = 0i64;
    }
    _InterlockedCompareExchange64((volatile signed __int64 *)&ExpPlatformBinaryLock, 17i64, 1i64);
  }
  v13 = (unsigned int)v24;
  if( (v24 & 1) == 0 )
  {
    v14 = (unsigned __int16 *)ExpPlatformBinaryTableInformation;
    if( *((_BYTE *)ExpPlatformBinaryTableInformation + 64) != 1
      || *((_BYTE *)ExpPlatformBinaryTableInformation + 65) != 1
      || (v15 = *((unsigned __int16 *)ExpPlatformBinaryTableInformation + 33), (v15 & 1) != 0)
      || (v16 = *(_LARGE_INTEGER *)((char *)ExpPlatformBinaryTableInformation + 56), !v16.QuadPart)
      || *((_DWORD *)ExpPlatformBinaryTableInformation + 10) != 1 )
    {
      v8 = -1073741701;
      goto LABEL_50;
    }
    v17 = *((unsigned int *)ExpPlatformBinaryTableInformation + 13);
    if( (unsigned int)v17 > Length || v15 > (unsigned int)v24 )
    {
      v8 = -1073741789;
      *((_DWORD *)SystemInformation + 6) = v17;
      *((_DWORD *)SystemInformation + 7) = v14[33];
      goto LABEL_50;
    }
    NumberOfBytes = *((unsigned int *)ExpPlatformBinaryTableInformation + 13);
    MmMapIoSpaceEx(v16, v17, 2ui64);
    v19 = v18;
    BaseAddress = v18;
    if( !v18 )
    {
      v8 = -1073741670;
      goto LABEL_50;
    }
    *(_QWORD *)SystemInformation = *((_QWORD *)v14 + 7);
    if( PreviousMode )
      ProbeForWrite((VOID *)Address, Length, 4ui64);
    memmove((UINT8 *)Address, v19, *((unsigned int *)v14 + 13));
    v20 = v14[33];
    if( v20 )
    {
      if( PreviousMode )
      {
        ProbeForWrite(dst, v13, 2ui64);
        v20 = v14[33];
      }
      memmove(dst, (UINT8 *)v14 + 68, v20);
    }
    v8 = 0;
    v5 = 1;
LABEL_11:
    if( !v5 )
      goto LABEL_12;
    goto LABEL_50;
  }
  v8 = -1073741811;
LABEL_50:
  if( _InterlockedCompareExchange64((volatile signed __int64 *)&ExpPlatformBinaryLock, 0i64, 17i64) != 17 )
    ExfReleasePushLockShared((INT64 *)&ExpPlatformBinaryLock);
  KeAbPostRelease(&ExpPlatformBinaryLock);
  KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
LABEL_12:
  if( BaseAddress )
    MmUnmapIoSpace(BaseAddress, NumberOfBytes);
  if( v4 )
    ExFreePoolWithTag(v4, 0x54425057u);
  return(unsigned int)v8;
}

Referenced by:

ExpQuerySystemInformation