VfProbeAndCaptureUnicodeStringBuffer
NTSTATUS __stdcall VfProbeAndCaptureUnicodeStringBuffer(_UNICODE_STRING *Destination, POOL_TYPE PoolType){
__int64 Length;
unsigned __int16 v5;
wchar_t *Buffer;
VOID **PoolWithTag;
wchar_t *v8;
Length = Destination->Length;
if( (Length & 1) != 0 )
return -1073741811;
v5 = 0;
if( (_WORD)Length )
{
Buffer = Destination->Buffer;
if( (unsigned __int64)Buffer + Length > 0x7FFFFFFF0000i64 || (wchar_t *)((char *)Buffer + Length) < Buffer )
MEMORY[0x7FFFFFFF0000] = 0;
PoolWithTag = ExAllocatePoolWithTag((unsigned int)PoolType, Destination->Length, 1129539158i64);
v8 = (wchar_t *)PoolWithTag;
if( !PoolWithTag )
return -1073741801;
memmove(PoolWithTag, Destination->Buffer, Destination->Length);
Destination->Buffer = v8;
v5 = Destination->Length;
}
else
{
Destination->Buffer = (wchar_t *)MmBadPointer;
}
Destination->MaximumLength = v5;
return 0;
}Referenced by:
NtSetSystemInformation
VfProbeAndCaptureUnicodeString