CmpQueryFileSecurityDescriptor
NTSTATUS __stdcall CmpQueryFileSecurityDescriptor(PVOID FileHandle, PVOID *SecurityDescriptor){
VOID *PoolWithTag;
int v5;
NTSTATUS result;
SIZE_T NumberOfBytes;
PoolWithTag = 0i64;
LODWORD(NumberOfBytes) = 0;
v5 = ZwQuerySecurityObject(FileHandle, 4ui64, 0i64, 0i64, &NumberOfBytes);
if( v5 == -1073741789 )
{
PoolWithTag = ExAllocatePoolWithTag(PagedPool, (unsigned int)NumberOfBytes, 0x64734D43ui64);
if( PoolWithTag )
{
v5 = ZwQuerySecurityObject(FileHandle, 4ui64, PoolWithTag, (unsigned int)NumberOfBytes, &NumberOfBytes);
if( v5 < 0 )
{
ExFreePoolWithTag(PoolWithTag, 0);
PoolWithTag = 0i64;
}
}
else
{
v5 = -1073741670;
}
}
else if( !v5 )
{
v5 = -1073741823;
}
result = v5;
*SecurityDescriptor = PoolWithTag;
return result;
}Referenced by:
CmpInitCmRM
CmpInitHiveFromFile
CmpLogHiveFileInaccessible
CmpOpenHiveFile
CmpStartRMLog