CVE-2025-46294 - Microsoft IIS Shortname Information Disclosure Vulnerability

CVE-2025-46294 - Microsoft IIS Shortname Information Disclosure Vulnerability

CVE ID : CVE-2025-46294 Published : Dec. 16, 2025, 6:16 p.m. | 1 hour, 54 minutes ago Description : To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully addressed in FileMaker Server 22.0.4. The IIS Shortname Vulnerability exploits how Microsoft IIS handles legacy 8.3 short filenames, allowing attackers to infer the existence of files or directories by crafting requests with the tilde (~) character. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Dec. 16, 2025
Affected Product: Windows

Source: Telegram CVE Monitor