Usually some variant of: The PDF file contains binary data somewhere within it that will cause a particular PDF reader to misallocate memory. Because data and code are jammed next to each other when you run a program, a clever memory misallocation can be used to rewrite the program (the PDF reader) as it executes in order to execute whatever malicious commands the author of said PDF file intends.
The typical defenses against these attacks include:
* Exploit mitigation tools, such as EMET
* Writing applications to be more memory-safe
* Various other tactics, many of them disingenuous.