SeGetImageRequiredSigningLevel
INT64 __stdcall SeGetImageRequiredSigningLevel(
_FILE_OBJECT *FileObject,
UINT64 SecureType,
UINT8 RequestedSigningLevel,
UINT8 ExistingSigningLevel,
UINT8 *SigningLevel){
unsigned int IsUntrustedObject;
_FILE_OBJECT *v7;
char v8;
__int64 v9;
UINT8 v10;
char v12;
char v13;
char UntrustedObject[22];
IsUntrustedObject = 0;
v12 = 0;
v13 = 0;
v7 = FileObject;
UntrustedObject[0] = 0;
if( qword_140C1D930 )
return(unsigned int)((__int64(__fastcall *)(_FILE_OBJECT *, UINT64, UINT8, UINT8, UINT8 *))qword_140C1D930)(
FileObject,
SecureType,
RequestedSigningLevel,
ExistingSigningLevel,
SigningLevel);
v8 = (char)SeILSigningPolicy;
if( !(_BYTE)SeILSigningPolicy )
v8 = SeILSigningPolicyRuntime;
if( v8 == 2 && !RequestedSigningLevel )
{
*SigningLevel = 2;
return IsUntrustedObject;
}
if( RequestedSigningLevel == 2 )
{
if( !v8 )
{
*SigningLevel = 0;
return IsUntrustedObject;
}
}
else if( !RequestedSigningLevel )
{
LABEL_31:
*SigningLevel = RequestedSigningLevel;
return IsUntrustedObject;
}
if( (SecureType & 0x10) != 0 )
goto LABEL_31;
if( qword_140C1D900 )
{
LOBYTE(SecureType) = RequestedSigningLevel;
LOBYTE(FileObject) = ExistingSigningLevel;
if( (unsigned int)qword_140C1D900(FileObject, SecureType) )
goto LABEL_31;
}
v9 = *((_QWORD *)KeGetCurrentThread() + 23);
if( (*(_BYTE *)(v9 + 2170) & 7) != 0 || RequestedSigningLevel != 6 )
goto LABEL_31;
if( (*(_DWORD *)(v9 + 2512) & 0x800000) != 0 )
goto LABEL_18;
if( !qword_140C1D8F8 )
return(unsigned int)-1073741823;
IsUntrustedObject = qword_140C1D8F8(v7, &v12, &v13);
if( (IsUntrustedObject & 0x80000000) != 0 )
return IsUntrustedObject;
if( v12 || v13 )
goto LABEL_18;
IsUntrustedObject = RtlIsUntrustedObject(0i64, v7, (UINT8 *)UntrustedObject);
if( (IsUntrustedObject & 0x80000000) != 0 )
return IsUntrustedObject;
if( UntrustedObject[0] )
{
LABEL_18:
*SigningLevel = 6;
}
else if( (unsigned __int8)v8 < 2u )
{
*SigningLevel = 0;
}
else
{
v10 = 9;
if( v8 != 2 )
v10 = 6;
*SigningLevel = v10;
}
return IsUntrustedObject;
}Referenced by:
MiValidateExistingImage