From ec380f2cc9e90ae747d6102a04d1af598f23ca1c Mon Sep 17 00:00:00 2001 From: midipix Date: Jul 30 2016 17:41:43 +0000 Subject: __ntapi_tt_create_native_process_v2(): close resulting informational handles. --- diff --git a/src/process/ntapi_tt_create_native_process_v2.c b/src/process/ntapi_tt_create_native_process_v2.c index e0bd71b..2d058a0 100644 --- a/src/process/ntapi_tt_create_native_process_v2.c +++ b/src/process/ntapi_tt_create_native_process_v2.c @@ -211,6 +211,10 @@ int32_t __stdcall __ntapi_tt_create_native_process_v2( params->create_process_ext_params))) return status; + /* tidy up */ + __ntapi->zw_close(params->create_process_info->success_state.hfile); + __ntapi->zw_close(params->create_process_info->success_state.hsection); + if ((status = __ntapi->zw_query_information_process( params->hprocess, NT_PROCESS_BASIC_INFORMATION,