# wab32.dll 19041.388 vs 19041.804 (CVE-2021-24083, manual pair)

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [SecurityCheckMultiValueSimplePropTag](#securitycheckmultivaluesimpleproptag)
* [Modified](#modified)
	* [SecurityCheckPropArrayBuffer](#securitycheckproparraybuffer)
* [Modified (No Code Changes)](#modified-no-code-changes)

# Visual Chart Diff



```mermaid

flowchart LR

SecurityCheckPropArrayBuffer-3-old<--Match 73%-->SecurityCheckPropArrayBuffer-3-new

subgraph wab32-10.0.19041.804.dll
    SecurityCheckPropArrayBuffer-3-new
    subgraph Added
direction LR
SecurityCheckMultiValueSimplePropTag
end
end

subgraph wab32-10.0.19041.388.dll
    SecurityCheckPropArrayBuffer-3-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.9794%
"unmatched_funcs_len" : 1
"matched_funcs_len" : 4848
```



```mermaid
pie showData
    title Matched Function Similarity - 99.9794%
"matched_funcs_with_code_changes_len" : 1
"matched_funcs_with_non_code_changes_len" : 0
"matched_funcs_no_changes_len" : 4847
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location C:\tools\hugo\patchpalooza\ghidriff\CVE-2021-24083\ghidra_projects --project-name CVE-2021-24083 --symbols-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2021-24083\symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 --md-title wab32.dll 19041.388 vs 19041.804 (CVE-2021-24083, manual pair) wab32-10.0.19041.388.dll wab32-10.0.19041.804.dll
```


#### Verbose Args


<details>

```
--old ['C:\\tools\\hugo\\patchpalooza\\ghidriff\\CVE-2021-24083\\wab32-10.0.19041.388.dll'] --new [['C:\\tools\\hugo\\patchpalooza\\ghidriff\\CVE-2021-24083\\wab32-10.0.19041.804.dll']] --engine VersionTrackingDiff --output-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2021-24083\output --summary False --project-location C:\tools\hugo\patchpalooza\ghidriff\CVE-2021-24083\ghidra_projects --project-name CVE-2021-24083 --symbols-path C:\tools\hugo\patchpalooza\ghidriff\CVE-2021-24083\symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title wab32.dll 19041.388 vs 19041.804 (CVE-2021-24083, manual pair)
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/WAB32.DLL/6063AE83DF000/WAB32.DLL -O wab32.dll.x64.10.0.19041.388
wget https://msdl.microsoft.com/download/symbols/WAB32.DLL/93A77C2BDF000/WAB32.DLL -O wab32.dll.x64.10.0.19041.928
```


## Binary Metadata Diff


```diff
--- wab32-10.0.19041.388.dll Meta
+++ wab32-10.0.19041.804.dll Meta
@@ -1,44 +1,44 @@
-Program Name: wab32-10.0.19041.388.dll
+Program Name: wab32-10.0.19041.804.dll
 Language ID: x86:LE:64:default (4.7)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 180000000
 Maximum Address: ff0000184f
-# of Bytes: 900992
+# of Bytes: 901504
 # of Memory Blocks: 9
-# of Instructions: 158332
-# of Defined Data: 10110
-# of Functions: 2424
-# of Symbols: 23342
+# of Instructions: 158353
+# of Defined Data: 10114
+# of Functions: 2425
+# of Symbols: 23348
 # of Data Types: 1880
 # of Data Type Categories: 57
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.1.2
-Date Created: Tue Jul 28 09:14:31 SGT 2026
+Date Created: Tue Jul 28 09:14:42 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2021-24083/wab32-10.0.19041.388.dll
-Executable MD5: 4cfd750bb8aee13dd09c0b0143a076c9
-Executable SHA256: c19070b2b39678d7abaea720b117fb6e255b240683798af1331173a7834e131c
-FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2021-24083/wab32-10.0.19041.388.dll?MD5=4cfd750bb8aee13dd09c0b0143a076c9
+Executable Location: /C:/tools/hugo/patchpalooza/ghidriff/CVE-2021-24083/wab32-10.0.19041.804.dll
+Executable MD5: 4ff38a46eede48b84170a021cfb0076d
+Executable SHA256: ba6c5dbc59717dae2ee018c68e18de537c3f7514c865083a8487bf49e1932fa9
+FSRL: file:///C:/tools/hugo/patchpalooza/ghidriff/CVE-2021-24083/wab32-10.0.19041.804.dll?MD5=4ff38a46eede48b84170a021cfb0076d
 PDB Age: 1
 PDB File: wab32.pdb
-PDB GUID: de145106-d948-3670-56a7-8b6f70069a16
+PDB GUID: c5076bf5-7673-ee97-ce95-6691f796f964
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Microsoft (R) Contacts DLL
-PE Property[FileVersion]: 10.0.19041.388 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.19041.928 (WinBuild.160101.0800)
 PE Property[InternalName]: WAB32.DLL
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: WAB32.DLL
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.19041.388
+PE Property[ProductVersion]: 10.0.19041.928
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra wab32-10.0.19041.388.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra wab32-10.0.19041.388.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra wab32-10.0.19041.388.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra wab32-10.0.19041.804.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra wab32-10.0.19041.804.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra wab32-10.0.19041.804.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|1|
|deleted_funcs_len|0|
|modified_funcs_len|1|
|added_symbols_len|0|
|deleted_symbols_len|0|
|diff_time|16.88798427581787|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 2423, 'ExternalsName': 462, 'BSIM': 1})|
|items_to_process|2|
|diff_types|Counter({'code': 1, 'length': 1, 'address': 1, 'called': 1})|
|unmatched_funcs_len|1|
|total_funcs_len|4849|
|matched_funcs_len|4848|
|matched_funcs_with_code_changes_len|1|
|matched_funcs_with_non_code_changes_len|0|
|matched_funcs_no_changes_len|4847|
|match_func_similarity_percent|99.9794%|
|func_match_overall_percent|99.9794%|
|first_matches|Counter({'SymbolsHash': 2423, 'BSIM': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 2423
"ExternalsName" : 462
"BSIM" : 1
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 2423
"BSIM" : 1
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 1
"deleted_funcs_len" : 0
"modified_funcs_len" : 1
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 0
"deleted_symbols_len" : 0
```

## Strings


*No string differences found*

# Deleted

# Added

## SecurityCheckMultiValueSimplePropTag

### Function Meta



|Key|wab32-10.0.19041.804.dll|
| :---: | :---: |
|name|SecurityCheckMultiValueSimplePropTag|
|fullname|SecurityCheckMultiValueSimplePropTag|
|refcount|1|
|length|177|
|called||
|calling|SecurityCheckPropArrayBuffer|
|paramcount|2|
|address|180035270|
|sig|int __cdecl SecurityCheckMultiValueSimplePropTag(uchar * * param_1, ulong * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- SecurityCheckMultiValueSimplePropTag
+++ SecurityCheckMultiValueSimplePropTag
@@ -0,0 +1,58 @@
+
+/* int __cdecl SecurityCheckMultiValueSimplePropTag(unsigned char * __ptr64 __unaligned *
+   __ptr64,unsigned long * __ptr64) */
+
+int __cdecl SecurityCheckMultiValueSimplePropTag(uchar **param_1,ulong *param_2)
+
+{
+  short sVar1;
+  short *psVar2;
+  uint uVar3;
+  ulonglong uVar4;
+  uchar *puVar5;
+  int iVar6;
+  
+  psVar2 = (short *)*param_1;
+  iVar6 = 0;
+  if (0xb < *param_2) {
+    uVar3 = *param_2 - 0xc;
+    *param_2 = uVar3;
+    iVar6 = 0;
+    if (*(uint *)(psVar2 + 4) <= uVar3) {
+      *param_2 = uVar3 - *(int *)(psVar2 + 4);
+      sVar1 = *psVar2;
+      if (sVar1 == 0x1002) {
+        uVar4 = 2;
+      }
+      else if ((sVar1 == 0x1003) || (sVar1 == 0x1004)) {
+        uVar4 = 4;
+      }
+      else if (((sVar1 == 0x1005) || (sVar1 == 0x1006)) || (sVar1 == 0x1007)) {
+        uVar4 = 8;
+      }
+      else {
+        uVar4 = 8;
+        if ((sVar1 != 0x1014) && (sVar1 != 0x1040)) {
+          if (sVar1 == 0x1048) {
+            uVar4 = 0x10;
+          }
+          else {
+            uVar4 = 0;
+          }
+        }
+      }
+      if ((ulonglong)*(uint *)(psVar2 + 4) / (ulonglong)*(uint *)(psVar2 + 2) == uVar4) {
+        if (uVar4 == 0) {
+          puVar5 = *param_1;
+        }
+        else {
+          puVar5 = *param_1 + *(uint *)(psVar2 + 4);
+        }
+        iVar6 = 1;
+        *param_1 = puVar5 + 0xc;
+      }
+    }
+  }
+  return iVar6;
+}
+

```


# Modified


*Modified functions contain code changes*
## SecurityCheckPropArrayBuffer

### Match Info



|Key|wab32-10.0.19041.388.dll - wab32-10.0.19041.804.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.15|
|i_ratio|0.26|
|m_ratio|0.82|
|b_ratio|0.73|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|wab32-10.0.19041.388.dll|wab32-10.0.19041.804.dll|
| :---: | :---: | :---: |
|name|SecurityCheckPropArrayBuffer|SecurityCheckPropArrayBuffer|
|fullname|SecurityCheckPropArrayBuffer|SecurityCheckPropArrayBuffer|
|refcount|4|4|
|`length`|415|264|
|`called`|SecurityCheckSingleValue|SecurityCheckMultiValueSimplePropTag<br>SecurityCheckSingleValue|
|calling|CWABStorage::ReadPropArray<br>CWABStorage::_FindRecordsWithoutLocking<br>HrGetPropArrayFromFileRecord|CWABStorage::ReadPropArray<br>CWABStorage::_FindRecordsWithoutLocking<br>HrGetPropArrayFromFileRecord|
|paramcount|3|3|
|`address`|1800353e4|18003549c|
|sig|int __cdecl SecurityCheckPropArrayBuffer(uchar * param_1, ulong param_2, ulong param_3)|int __cdecl SecurityCheckPropArrayBuffer(uchar * param_1, ulong param_2, ulong param_3)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### SecurityCheckPropArrayBuffer Called Diff


```diff
--- SecurityCheckPropArrayBuffer called
+++ SecurityCheckPropArrayBuffer called
@@ -0,0 +1 @@
+SecurityCheckMultiValueSimplePropTag
```


### SecurityCheckPropArrayBuffer Diff


```diff
--- SecurityCheckPropArrayBuffer
+++ SecurityCheckPropArrayBuffer
@@ -1,90 +1,64 @@
 
 /* int __cdecl SecurityCheckPropArrayBuffer(unsigned char * __ptr64,unsigned long,unsigned long) */
 
 int __cdecl SecurityCheckPropArrayBuffer(uchar *param_1,ulong param_2,ulong param_3)
 
 {
-  ushort uVar1;
+  short sVar1;
   int iVar2;
-  ulonglong uVar3;
-  uint uVar4;
-  ulonglong uVar5;
+  uint uVar3;
   uint *local_res8;
   uint local_res10 [2];
-  uint local_res18 [4];
+  uint local_res18 [2];
   
-  if (param_3 != 0) {
-    uVar5 = 8;
-    do {
-      if (param_2 < 5) break;
-      if ((*(uint *)param_1 & 0x1000) == 0) {
-        if (param_2 < 4) {
-          return 0;
-        }
-        local_res8 = (uint *)((longlong)param_1 + 4);
-        local_res10[0] = param_2 - 4;
-        iVar2 = SecurityCheckSingleValue(*(ulong *)param_1,(uchar **)&local_res8,local_res10);
-        param_2 = local_res10[0];
-        if (iVar2 == 0) {
-          return 0;
-        }
+  local_res10[0] = param_2;
+  do {
+    if ((param_3 == 0) || (param_2 < 5)) {
+      return (uint)(param_3 == 0);
+    }
+    if ((*(uint *)param_1 & 0x1000) == 0) {
+      if (param_2 < 4) {
+        return 0;
       }
-      else {
-        uVar1 = (ushort)*(uint *)param_1;
-        if ((uVar1 == 0x1102) || (uVar1 - 0x101e < 2)) {
-          if (param_2 < 0xc) {
+      local_res8 = (uint *)((longlong)param_1 + 4);
+      local_res10[0] = param_2 - 4;
+      iVar2 = SecurityCheckSingleValue(*(ulong *)param_1,(uchar **)&local_res8,local_res10);
+LAB_0:
+      param_2 = local_res10[0];
+      if (iVar2 == 0) {
+        return 0;
+      }
+    }
+    else {
+      sVar1 = (short)*(uint *)param_1;
+      if ((sVar1 != 0x1102) && (sVar1 != 0x101e && sVar1 != 0x101f)) {
+        local_res8 = (uint *)param_1;
+        iVar2 = SecurityCheckMultiValueSimplePropTag((uchar **)&local_res8,local_res10);
+        goto LAB_0;
+      }
+      if (param_2 < 0xc) {
+        return 0;
+      }
+      local_res18[0] = *(uint *)((longlong)param_1 + 8);
+      if (param_2 - 0xc < local_res18[0]) {
+        return 0;
+      }
+      param_2 = (param_2 - 0xc) - local_res18[0];
+      local_res8 = (uint *)((longlong)param_1 + 0xc);
+      uVar3 = 0;
+      local_res10[0] = param_2;
+      if (*(uint *)((longlong)param_1 + 4) != 0) {
+        do {
+          iVar2 = SecurityCheckSingleValue(*(ulong *)param_1,(uchar **)&local_res8,local_res18);
+          if (iVar2 == 0) {
             return 0;
           }
-          local_res18[0] = *(uint *)((longlong)param_1 + 8);
-          if (param_2 - 0xc < local_res18[0]) {
-            return 0;
-          }
-          local_res8 = (uint *)((longlong)param_1 + 0xc);
-          param_2 = (param_2 - 0xc) - local_res18[0];
-          uVar3 = 0;
-          if (*(uint *)((longlong)param_1 + 4) != 0) {
-            do {
-              iVar2 = SecurityCheckSingleValue(*(ulong *)param_1,(uchar **)&local_res8,local_res18);
-              if (iVar2 == 0) {
-                return 0;
-              }
-              uVar4 = (int)uVar3 + 1;
-              uVar3 = (ulonglong)uVar4;
-            } while (uVar4 < *(uint *)((longlong)param_1 + 4));
-          }
-        }
-        else {
-          if (param_2 < 0xc) {
-            return 0;
-          }
-          uVar4 = *(uint *)((longlong)param_1 + 8);
-          if (param_2 - 0xc < uVar4) {
-            return 0;
-          }
-          param_2 = (param_2 - 0xc) - uVar4;
-          if (uVar1 == 0x1002) {
-            uVar3 = 2;
-          }
-          else if ((uVar1 == 0x1003) || (uVar1 == 0x1004)) {
-            uVar3 = 4;
-          }
-          else {
-            uVar3 = uVar5;
-            if ((((uVar1 != 0x1005) && (uVar1 != 0x1006)) && (uVar1 != 0x1007)) &&
-               (((uVar1 != 0x1014 && (uVar1 != 0x1040)) && (uVar3 = 0, uVar1 == 0x1048)))) {
-              uVar3 = 0x10;
-            }
-          }
-          if ((ulonglong)uVar4 / (ulonglong)*(uint *)((longlong)param_1 + 4) != uVar3) {
-            return 0;
-          }
-          local_res8 = (uint *)((longlong)param_1 + (ulonglong)uVar4 + 0xc);
-        }
+          uVar3 = uVar3 + 1;
+        } while (uVar3 < *(uint *)((longlong)param_1 + 4));
       }
-      param_3 = param_3 - 1;
-      param_1 = (uchar *)local_res8;
-    } while (param_3 != 0);
-  }
-  return (uint)(param_3 == 0);
+    }
+    param_3 = param_3 - 1;
+    param_1 = (uchar *)local_res8;
+  } while( true );
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname



<sub>Generated with `ghidriff` version: 1.0.0 on 2026-07-28T09:16:02</sub>