Telstra interview question

What is the difference between a vulnerability and an exploit?