And the /Launch function, which allows PDF documents to run embedded executable files, is currently being exploited by attackers in a widespread malicious message campaign that tries to trick users into opening a rigged PDF.
Sullivan spelled out his case in more detail in a post to the F-Secure security blog on Thursday. "Your customers are tired of the exploits and the complications that so many of today's PDF readers include," said Sullivan in a "Dear Microsoft" missive.
"They should write a really simplified viewer, one that just previews PDF," Sullivan added Friday in a telephone interview. "They don't even need to build it into the operating system. They can make it an optional download like they did the 'Save As PDF' add-in for Office."