According to this
advisory vulnerabilities exist in VMware GSX Server 2.5.1 and earlier,
and in VMware Workstation 4.0 and earlier releases. "By manipulating
the VMware GSX Server and VMware Workstation environment variables, a
program such as a shell session with root privileges could be started when
a virtual machine is launched. The user would then have full access to the
host."