Foxit Reader before 8.3.1 and PhantomPDF before 8.3.1 have an Arbitrary Write vulnerability, which allows remote attackers to execute arbitrary code via a crafted document.
https://www.foxitsoftware.com/support/security-bulletins.php
https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-2631