VfProbeAndCaptureUnicodeStringBuffer

NTSTATUS __stdcall VfProbeAndCaptureUnicodeStringBuffer(_UNICODE_STRING *Destination, POOL_TYPE PoolType){
  __int64 Length; 
  unsigned __int16 v5; 
  wchar_t *Buffer; 
  VOID **PoolWithTag; 
  wchar_t *v8; 

  Length = Destination->Length;
  if( (Length & 1) != 0 )
    return -1073741811;
  v5 = 0;
  if( (_WORD)Length )
  {
    Buffer = Destination->Buffer;
    if( (unsigned __int64)Buffer + Length > 0x7FFFFFFF0000i64 || (wchar_t *)((char *)Buffer + Length) < Buffer )
      MEMORY[0x7FFFFFFF0000] = 0;
    PoolWithTag = ExAllocatePoolWithTag((unsigned int)PoolType, Destination->Length, 1129539158i64);
    v8 = (wchar_t *)PoolWithTag;
    if( !PoolWithTag )
      return -1073741801;
    memmove(PoolWithTag, Destination->Buffer, Destination->Length);
    Destination->Buffer = v8;
    v5 = Destination->Length;
  }
  else
  {
    Destination->Buffer = (wchar_t *)MmBadPointer;
  }
  Destination->MaximumLength = v5;
  return 0;
}

Referenced by:

NtSetSystemInformation
VfProbeAndCaptureUnicodeString