If this presentation doesn't scare you then trust me, it should. slides (PDF) 27C3PDFs are currently the greatest vector for drive-by (malware installing) attacks and targeted attacks on business and government. A/V technology is extraordinarily poor at detecting these. The PDF format itself is so diverse and vague, that an A/V would need to be 100% bug-compatible with the parser in the vulnerable PDF reader. You can also do cool tricks like make a single PDF file that displays completely differently in several different readers.
Update: The video of the presentation has been uploaded to Youtube.
P.S. Note that the slides are a PDF and the presentation is on PDF hacking. I find that amusing, don't you?