Agreed - but there are occasions when people manage to run code anyway.

This is a failure in the next layer of defence - someone who conned your software (via a buffer overflow, or whatever) into running software shouldn't be able to get more rights on the system than that software had initially...

