3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000004, The thread's stack pointer was outside the legal stack
extents for the thread.
Arg2: ffffda017ece0010, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffffda017ecdff68, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 3781
Key : Analysis.Elapsed.mSec
Value: 9743
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 734
Key : Analysis.Init.Elapsed.mSec
Value: 4462
Key : Analysis.Memory.CommitPeak.Mb
Value: 94
Key : Analysis.Version.DbgEng
Value: 10.0.27704.1001
Key : Analysis.Version.Description
Value: 10.2408.27.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2408.27.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x139
Key : Bugcheck.Code.TargetModel
Value: 0x139
Key : FailFast.Name
Value: INCORRECT_STACK
Key : FailFast.Type
Value: 4
Key : Failure.Bucket
Value: 0x139_MISSING_GSFRAME_nt!KiFastFailDispatch
Key : Failure.Hash
Value: {1971a9b0-b7ec-89bf-0a51-10ac52818da5}
Key : Hypervisor.Enlightenments.Value
Value: 77057948
Key : Hypervisor.Enlightenments.ValueHex
Value: 497cf9c
Key : Hypervisor.Flags.AnyHypervisorPresent
Value: 1
Key : Hypervisor.Flags.ApicEnlightened
Value: 1
Key : Hypervisor.Flags.ApicVirtualizationAvailable
Value: 0
Key : Hypervisor.Flags.AsyncMemoryHint
Value: 0
Key : Hypervisor.Flags.CoreSchedulerRequested
Value: 0
Key : Hypervisor.Flags.CpuManager
Value: 1
Key : Hypervisor.Flags.DeprecateAutoEoi
Value: 0
Key : Hypervisor.Flags.DynamicCpuDisabled
Value: 1
Key : Hypervisor.Flags.Epf
Value: 0
Key : Hypervisor.Flags.ExtendedProcessorMasks
Value: 1
Key : Hypervisor.Flags.HardwareMbecAvailable
Value: 1
Key : Hypervisor.Flags.MaxBankNumber
Value: 0
Key : Hypervisor.Flags.MemoryZeroingControl
Value: 0
Key : Hypervisor.Flags.NoExtendedRangeFlush
Value: 0
Key : Hypervisor.Flags.NoNonArchCoreSharing
Value: 1
Key : Hypervisor.Flags.Phase0InitDone
Value: 1
Key : Hypervisor.Flags.PowerSchedulerQos
Value: 0
Key : Hypervisor.Flags.RootScheduler
Value: 0
Key : Hypervisor.Flags.SynicAvailable
Value: 1
Key : Hypervisor.Flags.UseQpcBias
Value: 0
Key : Hypervisor.Flags.Value
Value: 4853999
Key : Hypervisor.Flags.ValueHex
Value: 4a10ef
Key : Hypervisor.Flags.VpAssistPage
Value: 1
Key : Hypervisor.Flags.VsmAvailable
Value: 1
Key : Hypervisor.RootFlags.AccessStats
Value: 1
Key : Hypervisor.RootFlags.CrashdumpEnlightened
Value: 1
Key : Hypervisor.RootFlags.CreateVirtualProcessor
Value: 1
Key : Hypervisor.RootFlags.DisableHyperthreading
Value: 0
Key : Hypervisor.RootFlags.HostTimelineSync
Value: 1
Key : Hypervisor.RootFlags.HypervisorDebuggingEnabled
Value: 0
Key : Hypervisor.RootFlags.IsHyperV
Value: 1
Key : Hypervisor.RootFlags.LivedumpEnlightened
Value: 1
Key : Hypervisor.RootFlags.MapDeviceInterrupt
Value: 1
Key : Hypervisor.RootFlags.MceEnlightened
Value: 1
Key : Hypervisor.RootFlags.Nested
Value: 0
Key : Hypervisor.RootFlags.StartLogicalProcessor
Value: 1
Key : Hypervisor.RootFlags.Value
Value: 1015
Key : Hypervisor.RootFlags.ValueHex
Value: 3f7
Key : Stack.Pointer
Value: PRCBException
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 139
BUGCHECK_P1: 4
BUGCHECK_P2: ffffda017ece0010
BUGCHECK_P3: ffffda017ecdff68
BUGCHECK_P4: 0
FILE_IN_CAB: 1.dmp
FAULTING_THREAD: ffff9a853d6b7080
TRAP_FRAME: ffffda017ece0010 -- (.trap 0xffffda017ece0010)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff988b75099000 rbx=0000000000000000 rcx=0000000000000004
rdx=ffff988b750a0000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80351865865 rsp=ffffda017ece01a0 rbp=ffffda017ece0710
r8=ffff988b750a0000 r9=ffffda017ece0728 r10=ffff988b7509f480
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!RtlpGetStackLimitsEx+0x178015:
fffff803`51865865 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffffda017ecdff68 -- (.exr 0xffffda017ecdff68)
ExceptionAddress: fffff80351865865 (nt!RtlpGetStackLimitsEx+0x0000000000178015)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000004
Subcode: 0x4 FAST_FAIL_INCORRECT_STACK
PROCESS_NAME: AnimazeDesktop.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000004
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffffda01`7ecdfce8 fffff803`51812da9 : 00000000`00000139 00000000`00000004 ffffda01`7ece0010 ffffda01`7ecdff68 : nt!KeBugCheckEx
ffffda01`7ecdfcf0 fffff803`51813350 : 00000000`00000000 00000000`00000000 00000001`ffffffff fffffff6`00000020 : nt!KiBugCheckDispatch+0x69
ffffda01`7ecdfe30 fffff803`518111f2 : ffffda01`7ece07c0 00000000`00000000 ffffda01`7ecdfa60 00000000`00000000 : nt!KiFastFailDispatch+0xd0
ffffda01`7ece0010 fffff803`51865865 : 000000a4`badfe860 00007ffd`69c502df ffffda01`7ece0710 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x332
ffffda01`7ece01a0 fffff803`51865f21 : ffffda01`7ece0710 00000000`00000000 ffff988b`7509f480 fffff803`00000003 : nt!RtlpGetStackLimitsEx+0x178015
ffffda01`7ece01d0 fffff803`51739536 : ffff988b`7509eac8 ffffda01`7ece0e20 ffff988b`7509eac8 00000000`00000000 : nt!RtlDispatchException+0x177821
ffffda01`7ece08f0 fffff803`517ff6e2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
ffffda01`7ece0fb0 fffff803`517ff6b0 : fffff803`51812ee5 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffff988b`7509e988 fffff803`51812ee5 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
ffff988b`7509e990 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0x125
SYMBOL_NAME: nt!KiFastFailDispatch+d0
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.5129
STACK_COMMAND: .process /r /p 0xffff9a8538d94340; .thread 0xffff9a853d6b7080 ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: 0x139_MISSING_GSFRAME_nt!KiFastFailDispatch
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {1971a9b0-b7ec-89bf-0a51-10ac52818da5}
Followup: MachineOwner
---------