Skype for Business (Lync) is gaining popularity among organizations that wish to benefit from high-quality communication within the corporation.
These organizations should realize, however, that as part of the Skype for Business deployment, Exchange Web Services (EWS) are required to be published externally in order to allow meeting information to be available to the Skype for Business client. This carries the risk of enabling a potential attacker to obtain access to all of the Exchange’s resources including emails, attachments and contacts.
These risks are divided into two categories:
- The EWS service allows for retrieving events, mails and attachments, tasks and contacts. Therefore, once exposed, all the Exchange data is also exposed.
- The deployment of EWS requires authentication, thus exposing the network to account lockout in case of a DDoS attack.
