AuthzBasepInitializeResourceClaimsFromSacl
__int64 __fastcall AuthzBasepInitializeResourceClaimsFromSacl(__int64 a1, __int64 a2){
int v3;
int *v4;
_DWORD *v5;
_DWORD *v6;
__int64 v7;
_QWORD *v8;
unsigned int v9;
int v11;
UINT64 v12;
int SecurityAttributesToken;
size_t v14;
SIZE_T NumberOfBytes;
int v16;
__int128 v17;
_QWORD *v18;
int P[64];
v18 = (_QWORD *)a2;
v16 = 2;
NumberOfBytes = 256i64;
v3 = 0;
v17 = 0i64;
v4 = P;
v5 = AuthzBasepMemAlloc(0x30ui64, a2);
v6 = v5;
if( !v5 )
return(unsigned int)-1073741801;
*v5 = 0;
v7 = a1 + 8;
v8 = v5 + 2;
v6[6] = 0;
v9 = 0;
v8[1] = v8;
*v8 = v8;
*((_QWORD *)v6 + 5) = v6 + 8;
*((_QWORD *)v6 + 4) = v6 + 8;
if( !*(_WORD *)(a1 + 4) )
goto LABEL_12;
while( 1 )
{
if( v4 && v4 != P )
ExFreePoolWithTag(v4, 0);
LODWORD(NumberOfBytes) = 256;
v4 = P;
if( *(_BYTE *)v7 != 18 || (*(_BYTE *)(v7 + 1) & 8) != 0 )
goto LABEL_7;
v11 = *(unsigned __int16 *)(v7 + 2) - 4 * *(unsigned __int8 *)(v7 + 9);
v3 = AuthzBasepConvertRelativeToAbsoluteTokenAttribute(
(UINT64 *)(v7 + 8 + 4 * (unsigned int)*(unsigned __int8 *)(v7 + 9) + 8),
(unsigned int)(v11 - 16),
(INT64)P,
&NumberOfBytes);
if( v3 == -1073741789 )
break;
LABEL_19:
if( v3 < 0 )
goto LABEL_8;
*((_QWORD *)&v17 + 1) = v4;
LOWORD(v17) = 1;
DWORD1(v17) = 1;
LODWORD(v14) = 0;
SecurityAttributesToken = AuthzBasepQuerySecurityAttributesToken(
v6,
(__int64)v4,
1u,
0i64,
v14,
(_DWORD *)&NumberOfBytes + 1);
v3 = SecurityAttributesToken;
if( SecurityAttributesToken == -1073741789 || SecurityAttributesToken == -1073741275 )
v3 = 0;
if( v3 < 0 )
goto LABEL_8;
if( HIDWORD(NumberOfBytes) <= 0x10 )
v3 = AuthzBasepSetSecurityAttributesToken(v6, &v16, (__int64)&v17);
if( v3 < 0 )
goto LABEL_8;
LABEL_7:
++v9;
v7 += *(unsigned __int16 *)(v7 + 2);
if( v9 >= *(unsigned __int16 *)(a1 + 4) )
goto LABEL_8;
}
v4 = (int *)AuthzBasepMemAlloc((unsigned int)NumberOfBytes, v12);
if( v4 )
{
v3 = AuthzBasepConvertRelativeToAbsoluteTokenAttribute(
(UINT64 *)(v7 + 4 * (*(unsigned __int8 *)(v7 + 9) + 4i64)),
(unsigned int)(v11 - 16),
(INT64)v4,
&NumberOfBytes);
goto LABEL_19;
}
v3 = -1073741801;
LABEL_8:
if( v4 && v4 != P )
ExFreePoolWithTag(v4, 0);
if( v3 < 0 )
{
AuthzBasepFreeSecurityAttributesList(v6);
ExFreePoolWithTag(v6, 0);
}
else
{
LABEL_12:
*v18 = v6;
}
return(unsigned int)v3;
}Referenced by:
SeAccessCheckByTypeWithAdminlessChecks
SeAccessCheckWithHintWithAdminlessChecks
SeExamineSacl
SepAccessCheckAndAuditAlarmWithAdminlessChecks
SepCommonAccessCheckExWithAdminlessChecks
SepExamineSaclEx
SepFilterCheck
SepMaximumAccessCheck
SepMaximumAccessCheckEx
SepNormalAccessCheck
SepNormalAccessCheckEx