I think we all know better than to download executable programs (.exe's) from untrusted sources and run them. Opening a Word document from an untrusted source could be dangerous. Now, even opening a PDF file on a fully patched Windows machine with excellent, up-to-date anti-virus and malware software could cause your machine to get owned.
Didier Stevens, who has written some great PDF analysis tools, published a disturbing blog post the other day. He demonstrates how to use an existing feature in PDF to execute a program on someone's computer when they open the document. Adobe Acrobat Reader displays a message first, but the message can be changed to social engineer someone into clicking the Open button on the message. And my favorite PDF reader, Foxit, does not even display this message. Disabling javascript does not help. Read More...