CmUpdateFeatureUsageSubscription
INT64 __stdcall CmUpdateFeatureUsageSubscription(PVOID Src, size_t Size, KPROCESSOR_MODE AccessMode){
UINT64 v4;
UINT8 *v6;
bool v7;
INT64 v8;
unsigned int updated;
UINT8 *TransientPoolWithQuotaTag;
INT64 v11;
unsigned int v12;
UINT64 v14;
int GrantedAccess[3];
UINT8 *v16;
struct _SECURITY_SUBJECT_CONTEXT SubjectSecurityContext;
INT64 AccessStatus;
v4 = (unsigned int)Size;
LODWORD(AccessStatus) = 0;
GrantedAccess[0] = 0;
memset(&SubjectSecurityContext, 0, sizeof(SubjectSecurityContext));
v6 = 0i64;
SeCaptureSubjectContext(&SubjectSecurityContext);
LODWORD(v14) = 0;
v7 = SeAccessCheck(
CmFcFeatureConfigSecurityDescriptor,
&SubjectSecurityContext,
0,
2ui64,
v14,
0i64,
&CmFcFeatureConfigMapping,
AccessMode,
(UINT64 *)GrantedAccess,
&AccessStatus);
SeReleaseSubjectContext(&SubjectSecurityContext);
if( !v7 )
{
updated = AccessStatus;
goto LABEL_12;
}
if( (unsigned int)v4 < 4 )
goto LABEL_4;
TransientPoolWithQuotaTag = (UINT8 *)CmpAllocateTransientPoolWithQuotaTag(v8, v4, 0x63466D43ui64);
v6 = TransientPoolWithQuotaTag;
v16 = TransientPoolWithQuotaTag;
if( TransientPoolWithQuotaTag )
{
memmove(TransientPoolWithQuotaTag, (UINT8 *)Src, v4);
v11 = *(unsigned int *)v6;
v12 = 20 * v11;
if( (unsigned __int64)(20 * v11) > 0xFFFFFFFF || v12 + 4 < v12 )
{
updated = -1073741811;
}
else
{
if( v12 + 4 != (_DWORD)v4 )
{
LABEL_4:
updated = -1073741820;
goto LABEL_12;
}
updated = CmFcManagerUpdateFeatureUsageSubscriptions(v11, (INT64 *)(v6 + 4), (unsigned int)v11);
}
}
else
{
updated = -1073741670;
}
LABEL_12:
if( v6 )
CmSiFreeMemory((PPRIVILEGE_SET)v6);
return updated;
}Referenced by:
NtSetSystemInformation