Even if this is inside a VM, it might give the wrong message to someone wanting to try this for themselves.
http://www.cvedetails.com/vulnerability-list/vendor_id-93/pr...
Then a compromise would need to be:
Local VM user -> root VM user -> local LiveCD user -> root liveCD user -> hardware exploits
Even if this is inside a VM, it might give the wrong message to someone wanting to try this for themselves.