Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.
http://www.vupen.com/english/advisories/2008/0905/references
http://www.vupen.com/english/advisories/2007/3229
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html
http://www.vmware.com/support/server/doc/releasenotes_server.html
http://www.vmware.com/support/player2/doc/releasenotes_player2.html
http://www.vmware.com/support/player/doc/releasenotes_player.html
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html
http://www.vmware.com/security/advisories/VMSA-2008-0005.html
http://www.securityfocus.com/bid/28289
http://www.securityfocus.com/bid/28276
http://www.securityfocus.com/archive/1/489739/100/0/threaded
http://secunia.com/advisories/26890
http://lists.vmware.com/pipermail/security-announce/2008/000008.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html