SepAssemblePrivileges
VOID __stdcall SepAssemblePrivileges(
UINT64 PrivilegeCount,
UINT8 SystemSecurity,
UINT8 WriteOwner,
UINT8 Relabel,
PRIVILEGE_SET **Privileges){
unsigned int *PoolWithTag;
unsigned int *v9;
__int64 v10;
if( Privileges )
{
if( (_DWORD)PrivilegeCount )
{
PoolWithTag = (unsigned int *)ExAllocatePoolWithTag(
PagedPool,
(unsigned int)(12 * (PrivilegeCount - 1) + 20),
0x72506553ui64);
v9 = PoolWithTag;
if( PoolWithTag )
{
*PoolWithTag = 0;
PoolWithTag[1] = 0;
v10 = 0i64;
if( SystemSecurity )
{
*((_QWORD *)v9 + 1) = *(_QWORD *)SeSecurityPrivilege;
v9[3 * (*v9)++ + 4] = 0x80000000;
v10 = *v9;
}
if( WriteOwner )
{
*(_QWORD *)&v9[3 * v10 + 2] = SeTakeOwnershipPrivilege;
v9[3 * (*v9)++ + 4] = 0x80000000;
v10 = *v9;
}
if( Relabel )
{
*(_QWORD *)&v9[3 * v10 + 2] = SeRelabelPrivilege;
v9[3 * (*v9)++ + 4] = 0x80000000;
}
*Privileges = (PRIVILEGE_SET *)v9;
}
}
}
}Referenced by:
SepAccessCheck
SepAccessCheckEx