The product does not initialize a critical resource.
Explicitly initialize the resource before use. If this is performed through an API function or standard procedure, follow all specified steps.
Pay close attention to complex conditionals that affect initialization, since some branches might not perform the initialization.
Avoid race conditions (CWE-362) during initialization routines.
Run or compile your product with settings that generate warnings about uninitialized variables or data.
Our security experts can help you identify and remediate CWE-909 vulnerabilities in your codebase.
Get Security Assessment