AuthzBasepEvaluateAceCondition
__int64 __fastcall AuthzBasepEvaluateAceCondition(
__int64 a1,
__int64 a2,
__int64 a3,
__int64 a4,
__int64 a5,
__int64 a6,
__int64 a7,
char *a8,
unsigned int a9,
char a10,
char a11,
int *a12){
unsigned int v12;
char *v13;
int SecurityAttributeAndValues;
__int64 v16;
__int64 v17;
int v18;
__int64 v19;
unsigned int v20;
int v21;
__int64 v22;
INT64 v23;
UINT8 v24;
PVOID *v25;
_QWORD *v26;
PVOID v27;
_DWORD *v28;
__int64 v29;
INT64 v30;
UINT8 v31;
PVOID *v32;
__int64 v33;
__int64 v34;
int v35;
int v36;
int *v37;
BYTE *v38;
PVOID *v39;
int v41;
INT64 v42;
bool v43;
INT64 v44;
int v45;
int v46;
INT64 v47;
INT64 v48;
INT64 v49;
int v50;
bool v51;
char v52;
int v53;
bool v54;
char v55;
__int64 v56;
__int64 v57;
int v58;
PVOID v59;
char v60[4];
BYTE v61[2];
INT64 v62;
int *v63;
char v64;
UINT64 StackPos;
unsigned int v66;
INT64 Result;
PVOID Token;
PVOID *v69;
INT64 result[2];
INT64 v71[2];
__int64 v72;
__int128 v73;
INT64 v74[2];
__int64 v75;
INT64 v76;
void *v77;
__int64 v78;
PVOID v79;
INT64 v80;
char *v81;
void *v82;
void *v83;
void *v84;
void *v85;
void *v86;
PCUNICODE_STRING String2;
__int128 v88;
__int128 v89;
char *v90;
__int128 v91;
PVOID P[2];
__int128 v93;
__int128 v94;
__int64 v95;
INT64 v96[2];
__int128 v97;
__int128 v98;
__int128 v99;
__int64 v100;
INT64 ResultStack[128];
v12 = 0;
v13 = a8;
SecurityAttributeAndValues = 0;
v82 = (void *)a5;
v85 = (void *)a6;
v86 = (void *)a3;
v77 = (void *)a2;
Token = (PVOID)a1;
v84 = (void *)a7;
v83 = (void *)a4;
v81 = a8;
v63 = a12;
LODWORD(StackPos) = 0;
LODWORD(v91) = 0;
*((_QWORD *)&v91 + 1) = 0i64;
memset((INT64)P, 0i64);
LOWORD(result[0]) = 0;
BYTE4(result[0]) = 0;
memset((INT64)result + 5, 0i64);
LODWORD(v62) = -1;
v90 = 0i64;
v80 = -1i64;
Result = 0i64;
v16 = 2i64;
LODWORD(v76) = 0;
*(_WORD *)v61 = 0;
WORD2(v62) = 0;
v60[0] = 0;
BYTE4(StackPos) = 0;
v64 = 0;
v79 = 0i64;
*a12 = -1;
P[1] = 0i64;
*((_QWORD *)&v97 + 1) = 0i64;
v88 = 0i64;
HIDWORD(v88) = 1;
v89 = 0i64;
if( !a1 || !a8 )
{
SecurityAttributeAndValues = -1073741811;
v37 = a12;
goto LABEL_40;
}
BYTE5(StackPos) = KeGetCurrentIrql() >= 2u;
if( a9 < 4 )
{
*a12 = 1;
SecurityAttributeAndValues = -2147483601;
v37 = a12;
goto LABEL_40;
}
if( *(_DWORD *)a8 != 2020897377 )
{
*a12 = 1;
SecurityAttributeAndValues = -2147483601;
v37 = a12;
goto LABEL_40;
}
AuthzBasepResetOperands((INT64)result, v61);
LODWORD(v17) = 4;
v66 = 0;
if( a9 <= 4 )
goto LABEL_61;
do
{
v18 = (unsigned __int8)v13[(unsigned int)v17];
if( v18 == 248 )
{
LABEL_14:
v19 = (unsigned int)(v17 + 1);
if( v12 == 2 )
{
if( HIDWORD(result[1]) == 1 )
goto LABEL_59;
LODWORD(v62) = AuthzBasepEvaluateAttribute(v71[0]);
SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, (unsigned int)v62);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
if( v61[0] )
ExFreePoolWithTag(*(PVOID *)(v57 + 24), 0);
v91 = *(_OWORD *)v96;
*(_OWORD *)P = v97;
v93 = v98;
v95 = v100;
v94 = v99;
v71[1] = v74[1];
v71[0] = (INT64)&v91;
v61[0] = v61[1];
*(_OWORD *)result = v73;
v72 = v75;
v61[1] = 0;
v73 = 0i64;
v75 = 0i64;
*(_OWORD *)v74 = 0i64;
memset((INT64)v96, 0i64);
v12 = 1;
v66 = 1;
}
if( a9 - (unsigned int)v19 < 4 )
goto LABEL_59;
v20 = *(_DWORD *)&v13[v19];
v21 = v19 + 4;
if( a9 - v21 < v20 )
goto LABEL_59;
if( v20 > 0xFFFE )
{
SecurityAttributeAndValues = -1073741562;
goto LABEL_60;
}
v90 = &v81[v21];
DWORD2(v89) = v20;
v22 = 9i64 * v12;
v78 = v22 * 8;
String2 = (PCUNICODE_STRING)&P[v22];
SecurityAttributeAndValues = AuthzBasepUnicodeStringFromOperandValue(
(__int64)&v88,
0,
(unsigned __int16 *)&P[v22],
&v61[v12]);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
v25 = &P[v22 - 2];
v26 = (PVOID *)((char *)&P[-1] + v78);
v69 = (PVOID *)((char *)&P[-1] + v78);
switch( (_BYTE)v18 )
{
case 0xF9:
v27 = v82;
if( !a11 )
v27 = v83;
*(_DWORD *)v25 = 3;
break;
case 0xFB:
v27 = v84;
if( !a11 )
v27 = v85;
*(_DWORD *)v25 = 5;
break;
case 0xFA:
v27 = v86;
*(_DWORD *)v25 = 4;
break;
case 0xFC:
v28 = Token;
v27 = Token;
*(_DWORD *)v25 = 6;
LABEL_25:
*v26 = v27;
v29 = 9i64 * v12;
*((_QWORD *)&v94 + v29 + 1) = 0i64;
v96[v29 - 1] = 0i64;
SecurityAttributeAndValues = AuthzBasepQuerySecurityAttributeAndValues((INT64)v25, v23, v24);
if( SecurityAttributeAndValues != -1073741275 )
goto LABEL_32;
if( *(_DWORD *)v25 == 2 )
{
v30 = *((unsigned int *)SepSingletonGlobal + 4);
if( (v30 & 1) != 0
&& (v28[50] & 0x20000) == 0
&& SepPotentialGlobalTableAttribute((UNICODE_STRING *)String2)
&& !BYTE4(StackPos) )
{
if( v64 )
{
LABEL_180:
v32 = v69;
*v69 = v79;
SecurityAttributeAndValues = AuthzBasepQuerySecurityAttributeAndValues((INT64)v25, v30, v31);
if( SecurityAttributeAndValues != -1073741275 )
goto LABEL_32;
*v32 = v77;
goto LABEL_29;
}
v58 = SepValidateAndCopyGlobalEntry((__int64)v77, &v79);
SecurityAttributeAndValues = v58;
if( v58 >= 0 )
{
v64 = 1;
goto LABEL_180;
}
BYTE4(StackPos) = 1;
if( v58 != -1073741275 )
goto LABEL_32;
}
}
v32 = v69;
LABEL_29:
if( BYTE5(StackPos) || *(_DWORD *)v25 != 2 )
goto LABEL_67;
*(_DWORD *)v25 = 7;
*v32 = 0i64;
SecurityAttributeAndValues = AuthzBasepQuerySecurityAttributeAndValues((INT64)v25, v30, v31);
LABEL_32:
if( SecurityAttributeAndValues >= 0 )
{
v33 = v78;
v34 = 5i64 * v12;
v71[v34] = (INT64)v25;
LOWORD(result[v34]) = *(_WORD *)((char *)&v93 + v33);
HIDWORD(result[v34]) = *(_DWORD *)((char *)&v93 + v33 + 8);
LABEL_34:
v35 = *(_DWORD *)v25;
LODWORD(v71[v34 + 1]) = 0;
*(__int64 *)((char *)&v72 + v34 * 8) = 0i64;
LODWORD(result[v34 + 1]) = 0;
v12 = v66 + 1;
HIDWORD(result[v34 + 1]) = v35;
LODWORD(v17) = v20 + v21;
v13 = v81;
LABEL_35:
v66 = v12;
continue;
}
if( SecurityAttributeAndValues != -1073741275 )
goto LABEL_60;
LABEL_67:
v34 = 5i64 * v12;
SecurityAttributeAndValues = 0;
LOWORD(result[v34]) = 0;
HIDWORD(result[v34]) = 0;
v71[v34] = 0i64;
if( v61[v12] )
{
ExFreePoolWithTag(*(PVOID *)((char *)&P[1] + v78), 0);
if( v12 >= 2ui64 )
_report_rangecheckfailure();
v61[v12] = 0;
}
goto LABEL_34;
default:
v27 = v77;
*(_DWORD *)v25 = 2;
break;
}
v28 = Token;
goto LABEL_25;
}
if( v18 == 162 )
{
LODWORD(v17) = v17 + 1;
if( !AuthzBasepIsValidExpression(0xA2ui64, (__int64)result, v12, v60) )
goto LABEL_59;
if( v12 == 1 )
{
LODWORD(v62) = AuthzBasepEvaluateAttribute(v71[0]);
v41 = v62;
AuthzBasepResetOperands((INT64)result, v61);
}
else
{
SecurityAttributeAndValues = AuthzBasepPopResult(ResultStack, &StackPos, &v62);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
v41 = v62;
}
if( v41 == -1 )
v42 = 0xFFFFFFFFi64;
else
v42 = v41 == 0;
goto LABEL_53;
}
if( (_BYTE)v18 )
{
if( v18 != 134 )
{
if( v18 == 16 )
{
LABEL_11:
if( v12 == 2 )
{
if( HIDWORD(result[1]) == 1 )
goto LABEL_59;
LODWORD(v62) = AuthzBasepEvaluateAttribute(v71[0]);
SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, (unsigned int)v62);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
if( v61[0] )
ExFreePoolWithTag(*(PVOID *)(v56 + 24), 0);
v91 = *(_OWORD *)v96;
*(_OWORD *)P = v97;
v93 = v98;
v95 = v100;
v94 = v99;
v71[1] = v74[1];
v71[0] = (INT64)&v91;
v61[0] = v61[1];
*(_OWORD *)result = v73;
v72 = v75;
v61[1] = 0;
v73 = 0i64;
v75 = 0i64;
*(_OWORD *)v74 = 0i64;
memset((INT64)v96, 0i64);
v12 = 1;
}
SecurityAttributeAndValues = AuthzBasepGetConstantOperand(
&v13[(unsigned int)v17],
a9 - (unsigned int)v17,
(INT64)&result[5 * v12],
&v76);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
++v12;
LODWORD(v17) = v76 + v17;
goto LABEL_35;
}
switch( v13[(unsigned int)v17] )
{
case 1:
case 2:
case 3:
case 4:
case 24:
case 80:
case 81:
goto LABEL_11;
case -128:
case -127:
case -126:
case -125:
case -124:
case -123:
case -120:
case -114:
case -113:
goto LABEL_62;
case -121:
case -115:
LODWORD(v17) = v17 + 1;
if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
goto LABEL_59;
v44 = v71[0] != 0;
LODWORD(v62) = v71[0] != 0;
if( (_BYTE)v18 == 0x8D )
{
v44 = v71[0] == 0;
LODWORD(v62) = v71[0] == 0;
}
goto LABEL_74;
case -119:
case -117:
case -112:
case -110:
LODWORD(v17) = v17 + 1;
if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
{
SecurityAttributeAndValues = -1073741406;
if( !v60[0] )
goto LABEL_60;
LABEL_115:
v49 = 0xFFFFFFFFi64;
LODWORD(v62) = -1;
v50 = -1;
goto LABEL_127;
}
if( v60[0] )
{
v52 = BYTE5(v62);
}
else
{
v51 = (_BYTE)v18 == 0x89 || (_BYTE)v18 == 0x90;
SecurityAttributeAndValues = AuthzBasepMemberOf(
(INT64)result,
Token,
(unsigned __int8)a10,
a11,
v51,
(INT64)&v62 + 4);
v52 = BYTE4(v62);
BYTE5(v62) = BYTE4(v62);
}
if( SecurityAttributeAndValues < 0 )
goto LABEL_115;
if( v52 )
{
v49 = 1i64;
LODWORD(v62) = 1;
v50 = 1;
}
else
{
v49 = 0i64;
LODWORD(v62) = 0;
v50 = 0;
}
LABEL_127:
if( (((_BYTE)v18 + 112) & 0xFD) == 0 && v50 != -1 )
{
v49 = v50 == 0;
LODWORD(v62) = v50 == 0;
}
SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v49);
if( SecurityAttributeAndValues >= 0 )
goto LABEL_54;
goto LABEL_60;
case -118:
case -116:
case -111:
case -109:
LODWORD(v17) = v17 + 1;
if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
{
SecurityAttributeAndValues = -1073741406;
if( !v60[0] )
goto LABEL_60;
LABEL_134:
v44 = 0xFFFFFFFFi64;
LODWORD(v62) = -1;
v53 = -1;
goto LABEL_146;
}
if( v60[0] )
{
v55 = BYTE5(v62);
}
else
{
v54 = (_BYTE)v18 == 0x8A || (_BYTE)v18 == 0x91;
SecurityAttributeAndValues = AuthzBasepDeviceMemberOf(
(__int64)result,
(__int64)Token,
(unsigned __int8)a10,
a11,
v54,
(_BYTE *)&v62 + 4);
v55 = BYTE4(v62);
BYTE5(v62) = BYTE4(v62);
}
if( SecurityAttributeAndValues < 0 )
goto LABEL_134;
if( v55 )
{
v44 = 1i64;
LODWORD(v62) = 1;
v53 = 1;
}
else
{
v44 = 0i64;
LODWORD(v62) = 0;
v53 = 0;
}
LABEL_146:
if( (((_BYTE)v18 + 111) & 0xFD) == 0 && v53 != -1 )
{
v44 = v53 == 0;
LODWORD(v62) = v53 == 0;
}
LABEL_74:
SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v44);
if( SecurityAttributeAndValues >= 0 )
goto LABEL_54;
goto LABEL_60;
case -96:
case -95:
LODWORD(v17) = v17 + 1;
if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
goto LABEL_59;
if( v12 == 2 )
{
LODWORD(Result) = AuthzBasepEvaluateAttribute(v71[0]);
v45 = AuthzBasepEvaluateAttribute(v74[0]);
HIDWORD(Result) = v45;
}
else
{
if( v12 == 1 )
{
LODWORD(Result) = AuthzBasepEvaluateAttribute(v71[0]);
}
else
{
SecurityAttributeAndValues = AuthzBasepPopResult(ResultStack, &StackPos, &Result);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
}
SecurityAttributeAndValues = AuthzBasepPopResult(ResultStack, &StackPos, (INT64 *)((char *)&Result + 4));
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
v45 = HIDWORD(Result);
}
if( (_BYTE)v18 == 0xA0 )
{
if( !v46 || !v45 )
goto LABEL_100;
if( v46 == -1 || v45 == -1 )
goto LABEL_95;
}
else if( v46 != 1 && v45 != 1 )
{
if( v46 != -1 && v45 != -1 )
{
LABEL_100:
v47 = 0i64;
LODWORD(v62) = 0;
goto LABEL_103;
}
LABEL_95:
v47 = 0xFFFFFFFFi64;
goto LABEL_102;
}
v47 = 1i64;
LABEL_102:
LODWORD(v62) = v47;
LABEL_103:
SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v47);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
break;
case -93:
LODWORD(v17) = v17 + 1;
if( !AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
{
SecurityAttributeAndValues = -1073741406;
if( !v60[0] )
goto LABEL_60;
LABEL_107:
v48 = 0xFFFFFFFFi64;
goto LABEL_108;
}
if( v60[0] )
goto LABEL_107;
AuthzBasepComputeExpression(v18, (INT64)result, &v80);
if( v80 == -1 )
goto LABEL_107;
v48 = v80 != 0;
LABEL_108:
LODWORD(v62) = v48;
SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v48);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
AuthzBasepResetOperands((INT64)result, v61);
continue;
case -7:
case -6:
case -5:
case -4:
goto LABEL_14;
default:
goto LABEL_59;
}
goto LABEL_54;
}
LABEL_62:
LODWORD(v17) = v17 + 1;
if( AuthzBasepIsValidExpression((unsigned __int8)v18, (__int64)result, v12, v60) )
{
if( !v60[0] )
{
AuthzBasepEvaluateExpression(v18, (INT64)result, (BOOL *)&v62);
v42 = (unsigned int)v62;
if( ((_BYTE)v18 == 0x8E || (_BYTE)v18 == 0x8F) && (_DWORD)v62 != -1 )
{
v42 = (_DWORD)v62 == 0;
LODWORD(v62) = v62 == 0;
}
LABEL_53:
SecurityAttributeAndValues = AuthzBasepPushResult(ResultStack, &StackPos, v42);
if( SecurityAttributeAndValues < 0 )
goto LABEL_60;
LABEL_54:
AuthzBasepResetOperands((INT64)result, v61);
v12 = 0;
v66 = 0;
continue;
}
}
else
{
SecurityAttributeAndValues = -1073741406;
if( !v60[0] )
goto LABEL_60;
}
v42 = 0xFFFFFFFFi64;
LODWORD(v62) = -1;
goto LABEL_53;
}
while( 1 )
{
v17 = (unsigned int)(v17 + 1);
v43 = (_DWORD)v17 == a9;
if( (unsigned int)v17 >= a9 )
break;
if( v13[v17] )
{
v43 = (_DWORD)v17 == a9;
break;
}
}
if( !v43 )
{
LABEL_59:
SecurityAttributeAndValues = -1073741406;
goto LABEL_60;
}
}
while( (unsigned int)v17 < a9 );
if( (_DWORD)StackPos == 1 )
{
v36 = ResultStack[0];
LABEL_39:
v37 = v63;
v16 = 2i64;
*v63 = v36;
goto LABEL_40;
}
if( !(_DWORD)StackPos && v12 == 1 )
{
v36 = AuthzBasepEvaluateAttribute(v71[0]);
goto LABEL_39;
}
LABEL_60:
v16 = 2i64;
LABEL_61:
v37 = v63;
LABEL_40:
v38 = v61;
v39 = &P[1];
do
{
if( *v38 )
ExFreePoolWithTag(*v39, 0);
++v38;
v39 += 9;
--v16;
}
while( v16 );
if( v64 )
{
v59 = v79;
if( v79 )
{
AuthzBasepFreeSecurityAttributesList(v79);
ExFreePoolWithTag(v59, 0x74416553u);
}
}
if( SecurityAttributeAndValues < 0 )
*v37 = -1;
return(unsigned int)SecurityAttributeAndValues;
}Referenced by:
SeAccessCheckByTypeWithAdminlessChecks
SeAccessCheckWithHintWithAdminlessChecks
SeExamineSacl
SepAccessCheckAndAuditAlarmWithAdminlessChecks
SepCommonAccessCheckExWithAdminlessChecks
SepExamineSaclEx
SepFilterCheck
SepMaximumAccessCheck
SepMaximumAccessCheckEx
SepNormalAccessCheck
SepNormalAccessCheckEx
SepVerifyDesktopAppxPackageName