CmUpdateFeatureUsageSubscription

INT64 __stdcall CmUpdateFeatureUsageSubscription(PVOID Src, size_t Size, KPROCESSOR_MODE AccessMode){
  UINT64 v4; 
  UINT8 *v6; 
  bool v7; 
  INT64 v8; 
  unsigned int updated; 
  UINT8 *TransientPoolWithQuotaTag; 
  INT64 v11; 
  unsigned int v12; 
  UINT64 v14; 
  int GrantedAccess[3]; 
  UINT8 *v16; 
  struct _SECURITY_SUBJECT_CONTEXT SubjectSecurityContext; 
  INT64 AccessStatus; 
  v4 = (unsigned int)Size;
  LODWORD(AccessStatus) = 0;
  GrantedAccess[0] = 0;
  memset(&SubjectSecurityContext, 0, sizeof(SubjectSecurityContext));
  v6 = 0i64;
  SeCaptureSubjectContext(&SubjectSecurityContext);
  LODWORD(v14) = 0;
  v7 = SeAccessCheck(
         CmFcFeatureConfigSecurityDescriptor,
         &SubjectSecurityContext,
         0,
         2ui64,
         v14,
         0i64,
         &CmFcFeatureConfigMapping,
         AccessMode,
         (UINT64 *)GrantedAccess,
         &AccessStatus);
  SeReleaseSubjectContext(&SubjectSecurityContext);
  if( !v7 )
  {
    updated = AccessStatus;
    goto LABEL_12;
  }
  if( (unsigned int)v4 < 4 )
    goto LABEL_4;
  TransientPoolWithQuotaTag = (UINT8 *)CmpAllocateTransientPoolWithQuotaTag(v8, v4, 0x63466D43ui64);
  v6 = TransientPoolWithQuotaTag;
  v16 = TransientPoolWithQuotaTag;
  if( TransientPoolWithQuotaTag )
  {
    memmove(TransientPoolWithQuotaTag, (UINT8 *)Src, v4);
    v11 = *(unsigned int *)v6;
    v12 = 20 * v11;
    if( (unsigned __int64)(20 * v11) > 0xFFFFFFFF || v12 + 4 < v12 )
    {
      updated = -1073741811;
    }
    else
    {
      if( v12 + 4 != (_DWORD)v4 )
      {
LABEL_4:
        updated = -1073741820;
        goto LABEL_12;
      }
      updated = CmFcManagerUpdateFeatureUsageSubscriptions(v11, (INT64 *)(v6 + 4), (unsigned int)v11);
    }
  }
  else
  {
    updated = -1073741670;
  }
LABEL_12:
  if( v6 )
    CmSiFreeMemory((PPRIVILEGE_SET)v6);
  return updated;
}

Referenced by:

NtSetSystemInformation