SepSecureBootCheckForUpdates
INT64 __stdcall SepSecureBootCheckForUpdates(){
INT64 result;
PULONG ResultLength;
UINT64 v2;
ULONG v3;
void *KeyHandle;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
__int128 KeyValueInformation;
int v7;
KeyHandle = 0i64;
v3 = 0;
ObjectAttributes.Length = 48;
*(&ObjectAttributes.Length + 1) = 0;
memset(&ObjectAttributes.Attributes + 1, 0, 20);
ObjectAttributes.RootDirectory = 0i64;
v7 = 0;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)L"z|";
KeyValueInformation = 0i64;
ObjectAttributes.Attributes = 576;
LODWORD(result) = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
if( (int)result >= 0 )
{
LODWORD(result) = ZwQueryValueKey(
KeyHandle,
(PUNICODE_STRING)&stru_1400097A0,
KeyValuePartialInformation,
&KeyValueInformation,
0x14u,
&v3);
if( (int)result >= 0
&& *(_QWORD *)((char *)&KeyValueInformation + 4) == 0x400000004i64
&& HIDWORD(KeyValueInformation) )
{
LODWORD(v2) = 0;
LODWORD(ResultLength) = 0;
result = NtUpdateWnfStateData(&WNF_SBS_UPDATE_AVAILABLE, 0i64, 0i64, 0i64, 0i64, (UINT64)ResultLength, v2);
}
}
if( KeyHandle )
LODWORD(result) = ZwClose(KeyHandle);
return result;
}Referenced by:
SeSecureBootRegisterPolicy