CmpAdminSystemSecurityDescriptor

ACL *__fastcall CmpAdminSystemSecurityDescriptor(){
  unsigned __int8 *PoolWithTag; 
  unsigned __int8 *v1; 
  UINT64 v2; 
  unsigned __int8 *v3; 
  UINT64 v4; 
  UINT32 v5; 
  UINT32 v6; 
  struct _ACL *v7; 
  _ACL *v8; 
  NTSTATUS Acl; 
  int v10; 
  ACL *v11; 
  ACL *v12; 
  NTSTATUS SecurityDescriptor; 
  ULONG_PTR v14; 
  NTSTATUS v15; 
  ULONG_PTR v16; 
  struct _SID_IDENTIFIER_AUTHORITY IdentifierAuthority; 
  *(_WORD *)&IdentifierAuthority.Value[4] = 1280;
  *(_DWORD *)IdentifierAuthority.Value = 0;
  PoolWithTag = (unsigned __int8 *)ExAllocatePoolWithTag(PagedPool, 0xCui64, 0x20204D43ui64);
  v1 = (unsigned __int8 *)ExAllocatePoolWithTag(PagedPool, 0x10ui64, 0x20204D43ui64);
  v3 = v1;
  if( !PoolWithTag || !v1 )
    KeBugCheckEx(0x51u, 0xBui64, 1ui64, 0i64, 0i64);
  LOBYTE(v2) = 1;
  if( (int)RtlInitializeSid(PoolWithTag, &IdentifierAuthority, v2) < 0
    || (LOBYTE(v4) = 2, (int)RtlInitializeSid(v3, &IdentifierAuthority, v4) < 0) )
  {
    KeBugCheckEx(0x51u, 0xBui64, 2ui64, 0i64, 0i64);
  }
  *RtlSubAuthoritySid(PoolWithTag, 0i64) = 18;
  *RtlSubAuthoritySid(v3, 0i64) = 32;
  *RtlSubAuthoritySid(v3, 1ui64) = 544;
  v5 = 4 * (PoolWithTag[1] + v3[1]) + 40;
  v6 = v5;
  v7 = (struct _ACL *)ExAllocatePoolWithTag(PagedPool, v5, 0x20204D43ui64);
  v8 = v7;
  if( !v7 )
    KeBugCheckEx(0x51u, 0xBui64, 3ui64, 0i64, 0i64);
  Acl = RtlCreateAcl(v7, v5, 2u);
  if( Acl < 0 )
    KeBugCheckEx(0x51u, 0xBui64, 4ui64, Acl, 0i64);
  v10 = RtlpAddKnownAce(v8, 2ui64, 0i64, 0x1F01FFui64, PoolWithTag, 0);
  if( v10 < 0 || (v10 = RtlpAddKnownAce(v8, 2ui64, 0i64, 0x1F01FFui64, v3, 0), v10 < 0) )
    KeBugCheckEx(0x51u, 0xBui64, 5ui64, v10, 0i64);
  v11 = (ACL *)ExAllocatePoolWithTag(PagedPool, v5 + 40i64, 0x20204D43ui64);
  v12 = v11;
  if( !v11 )
    KeBugCheckEx(0x51u, 0xBui64, 6ui64, 0i64, 0i64);
  memmove((UINT8 *)&v11[5], (UINT8 *)v8, v6);
  SecurityDescriptor = RtlCreateSecurityDescriptor(v12, 1ui64);
  v14 = SecurityDescriptor;
  if( SecurityDescriptor < 0 )
  {
    ExFreePoolWithTag(v12, 0);
    KeBugCheckEx(0x51u, 0xBui64, 7ui64, v14, 0i64);
  }
  v15 = RtlSetDaclSecurityDescriptor(v12, 1u, v12 + 5, 0);
  v16 = v15;
  if( v15 < 0 )
  {
    ExFreePoolWithTag(v12, 0);
    KeBugCheckEx(0x51u, 0xBui64, 8ui64, v16, 0i64);
  }
  ExFreePoolWithTag(PoolWithTag, 0);
  ExFreePoolWithTag(v3, 0);
  ExFreePoolWithTag(v8, 0);
  return v12;
}

Referenced by:

CmInitSystem1