NTSTATUS
MmCopyVirtualMemory(
  IN  PEPROCESS FromProcess,
  IN  CONST VOID *FromAddress,
  IN  PEPROCESS ToProcess,
  OUT PVOID ToAddress,
  IN  SIZE_T BufferSize,
  IN  KPROCESSOR_MODE PreviousMode,
  OUT PSIZE_T NumberOfBytesCopied
  );

Routine Description:

    This routine examines a exception record and extracts the virtual
    address of an access violation, guard page violation, or in-page error.

Arguments:

    ExceptionPointers - Supplies a pointer to the exception record.

    ExceptionAddressConfirmed - Receives TRUE if the exception address was
                                reliably detected, FALSE if not.

    BadVa - Receives the virtual address which caused the access violation.

Return Value:

    EXECUTE_EXCEPTION_HANDLER