0: kd> !analyze -v
*******************************************************************************
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8040c1be5c9, The address that the exception occurred at
Arg3: fffffd0996bb6248, Exception Record Address
Arg4: fffffd0996bb5a60, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read
Key : Analysis.CPU.mSec
Value: 1984
Key : Analysis.Elapsed.mSec
Value: 85873
Key : Analysis.IO.Other.Mb
Value: 8
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 11
Key : Analysis.Init.CPU.mSec
Value: 234
Key : Analysis.Init.Elapsed.mSec
Value: 6707
Key : Analysis.Memory.CommitPeak.Mb
Value: 159
Key : Analysis.Version.DbgEng
Value: 10.0.27704.1001
Key : Analysis.Version.Description
Value: 10.2408.27.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2408.27.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e
Key : Bugcheck.Code.TargetModel
Value: 0x1000007e
Key : Dump.Attributes.AsUlong
Value: 1008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: AV_nt!RtlpNewSecurityObject
Key : Failure.Hash
Value: {b726a1ab-d83b-ba1d-5992-b57d75096095}
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8040c1be5c9
BUGCHECK_P3: fffffd0996bb6248
BUGCHECK_P4: fffffd0996bb5a60
FILE_IN_CAB: 092024-12281-01.dmp
DUMP_FILE_ATTRIBUTES: 0x1008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffe50d2dbb0040
EXCEPTION_RECORD: fffffd0996bb6248 -- (.exr 0xfffffd0996bb6248)
ExceptionAddress: fffff8040c1be5c9 (nt!RtlpNewSecurityObject+0x0000000000000e39)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000045e91344
Attempt to read from address 0000000045e91344
CONTEXT: fffffd0996bb5a60 -- (.cxr 0xfffffd0996bb5a60)
rax=0000000000000800 rbx=ffffbd0ed22a8800 rcx=0000000000000010
rdx=00000000000000ef rsi=0000000000000400 rdi=ffffbd0edc86d1a0
rip=fffff8040c1be5c9 rsp=fffffd0996bb6480 rbp=fffffd0996bb6590
r8=ffffbd0edc8680d4 r9=000000000000000c r10=0000000000000000
r11=0000000000005190 r12=ffffe50d4b40addc r13=0000000000000000
r14=ffffbd0ed22a8800 r15=0000000000008000
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
nt!RtlpNewSecurityObject+0xe39:
fffff804`0c1be5c9 440ba8440be945 or r13d,dword ptr [rax+45E90B44h] ds:002b:00000000`45e91344=????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: fffff8040c71d470: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000045e91344
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000045e91344
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
fffffd09`96bb6480 fffff804`0bd0fe2e : 00000000`00000000 00000000`00000000 00000000`00000300 fffffd09`96bb68a8 : nt!RtlpNewSecurityObject+0xe39
fffffd09`96bb67c0 fffff804`0c1bba08 : ffffe50d`2dacb6c0 fffffd09`96bb6920 ffffe50d`53883b50 00000000`00000000 : nt!SeAssignSecurityEx2+0x6e
fffffd09`96bb6820 fffff804`0c0b130e : ffffffff`ffffffff fffffd09`96bb6cb0 00000000`00000000 ffffffff`ffffffff : nt!ObInsertObjectEx+0x248
fffffd09`96bb6ad0 fffff804`0c0b1ba5 : ffffe50d`4f591040 ffffe50d`3dc4f080 fffffd09`96bb73d0 fffffd09`96bb6c18 : nt!PspInsertThread+0x3be
fffffd09`96bb6bb0 fffff804`0c1eed8b : ffffe50d`3dc4f080 fffffd09`96bb7960 ffffe50d`3dc4f080 00000000`00000000 : nt!PspCreateThread+0x29d
fffffd09`96bb6e60 fffff804`0be2b608 : ffff8001`97edf180 fffff804`0be1fb37 004fe07f`b4bbbdff 00000000`00000000 : nt!NtCreateThreadEx+0x28b
fffffd09`96bb76f0 fffff804`0be1baf0 : fffff804`0c1f0ccd 00000000`00000000 ffffe50d`3dbf3f68 ffff8001`980ce180 : nt!KiSystemServiceCopyEnd+0x28
fffffd09`96bb78f8 fffff804`0c1f0ccd : 00000000`00000000 ffffe50d`3dbf3f68 ffff8001`980ce180 00000000`00c50001 : nt!KiServiceLinkage
fffffd09`96bb7900 fffff804`0bd67ad9 : ffffe50d`3dbf3d00 ffffffff`ffffffff ffffe50d`3dbf3d00 00000000`00000001 : nt!RtlpCreateUserThreadEx+0x151
fffffd09`96bb7a40 fffff804`0bd40ecd : 00000000`00000000 ffffe50d`3dbf3e98 ffffe50d`3dbf3d00 fffff804`0bce93b7 : nt!ExpWorkerFactoryCreateThread+0x10d
fffffd09`96bb7b00 fffff804`0bd8ab29 : ffffe50d`3dbf3d00 00000000`00000080 00000000`00000000 ffffe50d`3dbf3f68 : nt!ExpWorkerFactoryCheckCreate+0x20d
fffffd09`96bb7b60 fffff804`0bd54d47 : ffffe50d`2dbb0040 fffff804`0bd8aa00 00000000`00000000 00000000`00000000 : nt!ExpWorkerFactoryManagerThread+0x129
fffffd09`96bb7bb0 fffff804`0be1b174 : ffff8001`97e51180 ffffe50d`2dbb0040 fffff804`0bd54cf0 00000000`00000000 : nt!PspSystemThreadStartup+0x57
fffffd09`96bb7c00 00000000`00000000 : fffffd09`96bb8000 fffffd09`96bb1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x34
SYMBOL_NAME: nt!RtlpNewSecurityObject+e39
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.22621.4169
STACK_COMMAND: .cxr 0xfffffd0996bb5a60 ; kb
BUCKET_ID_FUNC_OFFSET: e39
FAILURE_BUCKET_ID: AV_nt!RtlpNewSecurityObject
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {b726a1ab-d83b-ba1d-5992-b57d75096095}
Followup: MachineOwner
---------