While the majority of exploits we currently see in the wild are things I think the "defective lock" analogy works well for, there's a subset of attacks that would be equivalent to cutting the lock with bolt cutters.
In those cases, there are specially crafted tools that aren't exploiting a defective lock, they're destroying the basic premise that let the lock work.
I'd say that RowHammer fits that description pretty aptly. It's a cyberweapon. It's not an exploit.
It's so much of a weapon that (as far as I know, someone please correct me if I'm out of date!) there's still no known mitigation strategy that completely solves the problem. We have lots of partial mitigations, but nothing surefire yet.
So... it's both. We certainly have lots of defective locks, but we also have some very nasty tools that exploit some fundamental premises of our tech in clearly malicious ways, and were absolutely designed and implemented to do exactly that.
In this case, I feel that blaming NSA for the exploit and calling those "cyberweapons" is wrong. The entity who put the ransomware on top of them and deployed them built a weapon.
However, a government deliberately hiding results from their medical research, or misleading/exploiting their pharmacy industry would be in a dark ethical corner.