I was (negatively) surprised when a coworker, running an Ubuntu VM under VirtualBox, clicked on the menu option to install the VirtualBox Guest Additions (which inserts a virtual CD-ROM with the drivers), and the Ubuntu desktop asked if he wanted to run the installer from the CD!
Yes, it prompted before running, but it is well known that most people will just click "Yes" without even reading the text in a dialog box.