CmpCheckOpenAccessOnKeyBody
INT64 __fastcall CmpCheckOpenAccessOnKeyBody(
PVOID Object,
INT64 a2,
_DWORD *a3,
struct _ACCESS_STATE *a4,
CHAR a5,
CHAR a6,
_CM_TRANS *ObjectCreated,
INT64 a8,
INT64 a9){
__int16 v9;
LIST_ENTRY *v11;
INT64 i;
__int64 v14;
__int16 v15;
_LIST_ENTRY *Blink;
CHAR v17;
unsigned __int8 v18;
INT64 v19;
int v20;
__int64 v21;
_PRIVILEGE_SET *v22;
int started;
int v24;
_DWORD *v25;
int v26;
__int64 v27;
_PRIVILEGE_SET *v28;
int v29;
__int16 v30;
PPRIVILEGE_SET j;
PPRIVILEGE_SET v32;
__int16 Control_high;
_ETHREAD *CurrentThread;
_LUID Luid;
UINT8 v36;
unsigned int v37;
__int16 v38;
__int64 v39;
unsigned __int8 v40;
char v41;
_ETHREAD *v43;
_EPROCESS *CurrentThreadProcess;
INT64 v45;
NTSTATUS ServerSiloServiceSessionId;
INT64 v47;
INT64 v48;
LIST_ENTRY *v49;
__int64 v50;
_CM_TRANS *v51;
__int64 v52;
INT64 v53;
__int64 v54;
__int64 v55;
__int64 v56;
__int16 v57;
INT16 v58;
INT64 KcbAtLayerHeight;
INT64 v60;
_PRIVILEGE_SET *TransientPoolWithTag;
PPRIVILEGE_SET *Privileges;
_KPROCESSOR_MODE AccessMode;
int AccessStatus;
unsigned int GrantedAccess;
PPRIVILEGE_SET v66;
LIST_ENTRY *ListIterator;
__int128 v68;
PPRIVILEGE_SET v69[2];
INT64 v70[2];
PPRIVILEGE_SET v71[2];
v9 = *(_WORD *)(a2 + 2);
v11 = 0i64;
for( i = a2; v9 >= 0; --v9 )
{
if( v9 >= 2 )
v14 = *(_QWORD *)(*(_QWORD *)(i + 24) + 8i64 * v9 - 16);
else
v14 = *(_QWORD *)(i + 8i64 * v9 + 8);
v15 = *(_WORD *)(v14 + 66);
if( v15 && *(_BYTE *)(v14 + 65) == 1 )
break;
if( *(_DWORD *)(v14 + 40) != -1 )
{
v11 = (LIST_ENTRY *)v14;
if( v15 )
{
if( *(_BYTE *)(v14 + 65) )
break;
}
}
}
Blink = v11[5].Blink;
if( ObjectCreated )
{
v49 = v11 + 13;
ListIterator = 0i64;
LODWORD(v50) = CmListGetPrevElement(v11 + 13, &ListIterator, (INT64)a3);
v52 = v50;
if( v50 )
{
while( !CmEqualTrans(*(_QWORD *)(v52 + 56), (__int64)v51) || *(_DWORD *)(v52 + 68) != 9 )
{
LODWORD(v54) = CmListGetPrevElement(v49, &ListIterator, v53);
v52 = v54;
if( !v54 )
goto LABEL_9;
v51 = ObjectCreated;
}
Blink = *(_LIST_ENTRY **)(v52 + 88);
}
}
LABEL_9:
v17 = a6;
v18 = a5;
if( a6 && (int)CmpSetAccessStateForBackupRestore((INT64)a4, a5, &Blink[2], 1) < 0 )
goto LABEL_74;
v19 = *((_QWORD *)Object + 1);
v20 = *((_DWORD *)a4 + 6);
*(_OWORD *)v70 = 0i64;
WORD1(v70[0]) = -1;
v21 = *(_QWORD *)(v19 + 32);
*(_OWORD *)v71 = 0i64;
if( (*(_DWORD *)(v21 + 160) & 0x100000) == 0 )
{
v22 = 0i64;
started = 0;
goto LABEL_12;
}
if( (v20 & 0xD0026) == 0 )
{
v22 = 0i64;
started = 0;
goto LABEL_12;
}
if( (v20 & 0xD0002) != 0 )
{
started = -1073741790;
LABEL_98:
v22 = 0i64;
goto LABEL_12;
}
if( (*(_DWORD *)(v21 + 4152) & 0x2000) == 0 )
{
started = -1073741790;
goto LABEL_98;
}
if( *(_BYTE *)(v19 + 65) )
{
started = -1073741790;
goto LABEL_98;
}
started = CmpStartKcbStackForTopLayerKcb((INT64)v70, v19);
if( started < 0 )
goto LABEL_98;
v58 = *(_WORD *)(v19 + 66) - 1;
if( v58 < 0 )
{
LABEL_97:
v17 = a6;
goto LABEL_98;
}
while( 1 )
{
KcbAtLayerHeight = CmpGetKcbAtLayerHeight((INT64)v70, v58);
WORD1(v70[0]) = v58;
v60 = KcbAtLayerHeight;
if( CmpIsKeyStackDeleted((INT64)v70, 0i64) )
{
LABEL_95:
started = -1073741790;
LABEL_96:
v18 = a5;
goto LABEL_97;
}
if( (*(_DWORD *)(*(_QWORD *)(v60 + 32) + 160i64) & 0x100000) == 0 )
break;
if( (*(_DWORD *)(*(_QWORD *)(v19 + 32) + 4152i64) & 0x2000) == 0 || *(_BYTE *)(v19 + 65) )
goto LABEL_95;
if( --v58 < 0 )
goto LABEL_96;
}
v17 = a6;
v22 = 0i64;
v18 = a5;
started = 0;
LABEL_12:
if( v71[1] )
{
CmSiFreeMemory(v71[1]);
v22 = 0i64;
}
if( started < 0 || (v24 = *((_DWORD *)a4 + 6), v25 = a3, (v24 & a3[24]) != v24) )
{
LABEL_74:
v40 = 0;
*(_DWORD *)a9 = -1073741790;
v41 = 0;
goto LABEL_44;
}
if( v17 && !*((_DWORD *)a4 + 4) || !v24 && (*a3 & 0x1000) != 0 )
goto LABEL_43;
v26 = *((_DWORD *)Object + 12);
GrantedAccess = 0;
v66 = 0i64;
v68 = 0i64;
WORD1(v68) = -1;
*(_OWORD *)v69 = 0i64;
if( (v26 & 9) == 0 )
{
v27 = *((_QWORD *)Object + 1);
v28 = 0i64;
v29 = *(__int16 *)(v27 + 66);
v30 = *(_WORD *)(v27 + 66);
if( v29 >= 2 )
{
TransientPoolWithTag = (_PRIVILEGE_SET *)CmpAllocateTransientPoolWithTag(1ui64, 8i64 * (unsigned int)(v29 - 1));
v28 = TransientPoolWithTag;
if( !TransientPoolWithTag )
{
AccessStatus = -1073741670;
v36 = 0;
LABEL_39:
v25 = a3;
i = a2;
v17 = a6;
goto LABEL_40;
}
memset(TransientPoolWithTag, 0i64, 8 * (v29 - 1));
v30 = *(_WORD *)(v27 + 66);
v22 = 0i64;
}
LOWORD(v68) = v29;
v69[1] = v28;
WORD1(v68) = v30;
if( v30 )
{
v55 = *(_QWORD *)(v27 + 192);
if( v55 )
{
do
{
CmpSetKcbAtLayerHeight((__int64)&v68, v30, *(_QWORD *)(v55 + 16));
v55 = *(_QWORD *)(v56 + 24);
v30 = v57 - 1;
}
while( v55 );
v28 = v69[1];
v30 = WORD1(v68);
}
}
else
{
*((_QWORD *)&v68 + 1) = v27;
}
AccessStatus = (int)v22;
for( j = v22; v30 >= 0; --v30 )
{
if( v30 >= 2 )
v32 = (PPRIVILEGE_SET)*((_QWORD *)v28 + v30 - 2);
else
v32 = v69[v30 - 1];
Control_high = HIWORD(v32[3].Control);
if( Control_high && BYTE1(v32[3].Control) == 1 )
break;
if( v32[2].PrivilegeCount != -1 )
{
j = v32;
if( Control_high )
{
if( BYTE1(v32[3].Control) )
break;
}
}
}
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
Luid = j[4].Privilege[0].Luid;
--CurrentThread->Tcb.KernelApcDisable;
ExAcquireResourceSharedLite(*(_QWORD *)(*((_QWORD *)a4 + 6) + 48i64), 1);
if( *((_QWORD *)a4 + 4) )
{
v43 = (_ETHREAD *)KeGetCurrentThread();
--v43->Tcb.KernelApcDisable;
ExAcquireResourceSharedLite(*(_QWORD *)(*((_QWORD *)a4 + 4) + 48i64), 1);
}
LOBYTE(AccessMode) = v18;
v36 = (unsigned __int8)SeAccessCheck(
(PSECURITY_DESCRIPTOR)(*(_QWORD *)&Luid + 32i64),
(PSECURITY_SUBJECT_CONTEXT)a4 + 1,
1u,
*((_DWORD *)a4 + 4),
*((_DWORD *)a4 + 5),
&v66,
(PGENERIC_MAPPING)((char *)CmKeyObjectType + 76),
AccessMode,
&GrantedAccess,
&AccessStatus);
if( v66 )
{
SeAppendPrivileges(a4, v66);
CmSiFreeMemory(v66);
}
if( v36 )
{
v37 = GrantedAccess;
*((_DWORD *)a4 + 5) |= GrantedAccess;
*((_DWORD *)a4 + 4) &= ~(v37 | 0x2000000);
}
*((_WORD *)Object + 24) |= 2u;
v38 = *((_WORD *)Object + 24);
if( v18 )
{
SeOpenObjectAuditAlarmWithTransaction(
(_UNICODE_STRING *)CmKeyObjectType + 1,
Object,
0i64,
(VOID *)(*(_QWORD *)&Luid + 32i64),
a4,
0,
v36,
v18,
0i64,
(UINT8 *)a4 + 10);
v38 = *((_WORD *)Object + 24);
}
*((_WORD *)Object + 24) = v38 & 0xFFFD;
ExReleaseResourceLite(*(PERESOURCE *)(*((_QWORD *)a4 + 6) + 48i64));
KeLeaveCriticalRegion();
v39 = *((_QWORD *)a4 + 4);
if( v39 )
{
ExReleaseResourceLite(*(PERESOURCE *)(v39 + 48));
KeLeaveCriticalRegion();
}
goto LABEL_39;
}
AccessStatus = -1073741444;
v36 = 0;
LABEL_40:
if( v69[1] )
{
CmSiFreeMemory(v69[1]);
v25 = a3;
}
if( v36 )
{
LABEL_43:
v40 = 1;
*(_DWORD *)a9 = 0;
v41 = 0;
goto LABEL_44;
}
if( v17 )
goto LABEL_49;
LODWORD(Privileges) = AccessStatus;
if( (int)CmpVEPerformOpenAccessCheck(
(INT64)Object,
(INT64)ObjectCreated,
(INT64)a4,
v18,
(INT64)v25,
(UINT64)Privileges) >= 0 )
{
v40 = 1;
*(_DWORD *)a9 = 0;
v41 = 0;
goto LABEL_44;
}
if( KeGetCurrentThread()->PreviousMode == 1
&& (CurrentThreadProcess = (_EPROCESS *)PsGetCurrentThreadProcess(),
LODWORD(v45) = PsGetProcessServerSilo((INT64)CurrentThreadProcess),
ServerSiloServiceSessionId = PsGetServerSiloServiceSessionId(v45),
MmGetSessionIdEx(CurrentThreadProcess) != ServerSiloServiceSessionId)
&& (*((_DWORD *)a4 + 4) & 0xD0026) != 0
&& CmpCheckKeyOwnerForPca(i, v47, v48) )
{
v41 = 1;
v40 = 0;
*(_DWORD *)a9 = -1073741790;
}
else
{
LABEL_49:
v41 = 0;
v40 = 0;
*(_DWORD *)a9 = -1073741790;
}
LABEL_44:
*(_BYTE *)a8 = v41;
return v40;
}Referenced by:
CmpDoParseKey