If you keep IIS patched and up to date, you're ok...

As for the share, you over state it a bit: you need admin access to access administrative shares (C$, ...). Not that it can't be done, but it's not THAT easy..
Besides, just disable sharing if you're not using it..

Ammo