EtwpGetGuidSecurityDescriptor
INT64 __fastcall EtwpGetGuidSecurityDescriptor(_UNICODE_STRING *GuidName, VOID **SecurityDescriptor){
void *ValueData;
UINT64 v3;
NTSTATUS v6;
int v7;
VOID *PoolWithTag;
ULONG Length;
ULONG ValueType;
ValueData = 0i64;
v3 = 512i64;
ValueType = 0;
*SecurityDescriptor = 0i64;
for( Length = 512; ; v3 = Length )
{
if( ValueData )
ExFreePoolWithTag(ValueData, 0);
ValueData = ExAllocatePoolWithTag(PagedPool, (unsigned int)v3, 0x50777445ui64);
if( !ValueData )
break;
v6 = RtlQueryRegistryValueWithFallback(
EtwpMutableSecurityKeyHandle,
EtwpSecurityKeyHandle,
GuidName,
v3,
&ValueType,
ValueData,
&Length);
v7 = v6;
if( v6 != -2147483643 && v6 != -1073741789 )
{
v3 = Length;
goto LABEL_8;
}
}
v7 = -1073741670;
LABEL_8:
if( v7 >= 0 && ValueType == 3 )
{
if( SeValidSecurityDescriptor((unsigned int)v3, ValueData) )
{
PoolWithTag = ExAllocatePoolWithTag(PagedPool, v3, 0x50777445ui64);
*SecurityDescriptor = PoolWithTag;
if( PoolWithTag )
memmove((UINT8 *)PoolWithTag, (UINT8 *)ValueData, v3);
else
v7 = -1073741670;
}
else
{
v7 = -1073741703;
}
}
if( ValueData )
ExFreePoolWithTag(ValueData, 0);
return(unsigned int)v7;
}Referenced by:
EtwpGetSecurityDescriptorByGuid
EtwpInitializeSecurity