MiObtainReferencedSecureVad

INT64 __fastcall MiObtainReferencedSecureVad(UINT64 P3, INT64 *a2){
  _ETHREAD *CurrentThread; 
  __int64 v5; 
  UINT64 v6; 
  RTL_BALANCED_NODE *Address; 
  __int64 v8; 
  unsigned __int64 v9; 
  int v11; 
  *(_DWORD *)a2 = 0;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v5 = *((_QWORD *)CurrentThread + 23);
  --*((_WORD *)CurrentThread + 243);
  ExAcquirePushLockSharedEx(v5 + 1224, 0i64);
  *((_BYTE *)CurrentThread + 1304) |= 2u;
  if( (*(_DWORD *)(v5 + 1124) & 0x20) != 0 )
  {
    UNLOCK_ADDRESS_SPACE_SHARED((__int64)CurrentThread, v5);
    *(_DWORD *)a2 = -1073741558;
    return 0i64;
  }
  else
  {
    v6 = *(_QWORD *)(P3 + 8);
    Address = MiLocateAddress(v6);
    v8 = (__int64)Address;
    if( !Address )
      KeBugCheckEx(0x1Au, 0x15000ui64, v6, P3, 0i64);
    if( !_InterlockedIncrement((volatile signed __int32 *)&Address[1].Right + 1) )
      __fastfail(0xEu);
    --*((_WORD *)CurrentThread + 243);
    UNLOCK_ADDRESS_SPACE_SHARED((__int64)CurrentThread, v5);
    v9 = v6 >> 12;
    --*((_WORD *)CurrentThread + 243);
    ExAcquirePushLockExclusiveEx(v8 + 40, 0i64);
    *((_BYTE *)CurrentThread + 1304) |= 0x80u;
    KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
    if( (*(_DWORD *)(v8 + 48) & 4) != 0 )
    {
      MiWaitForVadDeletion(v8);
      MiUnlockAndDereferenceVad((PVOID)v8);
      v11 = -1073741558;
      if( (*(_DWORD *)(v5 + 1124) & 0x20) == 0 )
        v11 = -1073741664;
      *(_DWORD *)a2 = v11;
    }
    else
    {
      if( v9 >= (*(unsigned int *)(v8 + 24) | ((unsigned __int64)*(unsigned __int8 *)(v8 + 32) << 32))
        && v9 <= (*(unsigned int *)(v8 + 28) | ((unsigned __int64)*(unsigned __int8 *)(v8 + 33) << 32)) )
      {
        return v8;
      }
      MiUnlockAndDereferenceVad((PVOID)v8);
      *(_DWORD *)a2 = -1073741664;
    }
    return 0i64;
  }
}

Referenced by:

MiPerformImageHotPatch
MmStoreAllocateVirtualMemory
MmUnsecureVirtualMemory