Even a bug-free program might be exploitable.
That sounds like a bug
There are programs like sudo whose entire reason for existing is to enable privilege escalation. If you can find a way to make a user "sudo" something, that's an exploit, but it's not a bug in the program.
[delayed]
At that point you're exploiting the user, who is not a bug-free program