Using Skype for Business (Lync), the client interacts with the Exchange server to obtain meeting information. In order to implement this connection, the deployment of Skype for Business requires Exchange Web Services (EWS) published externally to the world.
This exposes the client to several threats:
- The deployment of EWS includes an authentication service, thus exposing the network to account lockout in case of a DDoS attack.
- The EWS service allows for retrieving events, mails and attachments, tasks and contacts. Therefore, once exposed, all the Exchange data is also exposed.
