Returning an empty descriptor like in the patch is enough to fix the bug of the appliction not starting, and allows basic usage of the program. For anyone who would like to make the options under the Security tab to work: there's a clear FIXME in the patch. So the patch does for now what the bugreport is about: allow the program to start.
Further note: MSDN says this function has been around since windows 2000. The fact that it (probably) never has been called by a program in wine, tells me that likely no other programs will suffer from the poor "implementation" like in this patch.