Alternatively, consider any program which loads dynamic shared libraries (called "plugins" in many contexts). The program itself might be bug free; any plugin that is loaded will run (typically) with the full priviledges and access of the program (and thus likely the user).
The user may have no idea that the plugin is malicious; the program remains bug-free (if it was beforehand).
At least with plugins most people have a general notion that they run some sort of code as they provide some new functionality.
Much more agregiously you can design harmless a looking format that can run arbitrary code e.g. .doc with VBS. I have a very hard time blaming an user who falls for that even though MS puts up a scary looking popup.
The user may have no idea that the plugin is malicious; the program remains bug-free (if it was beforehand).