Government contracts for software often include having the rights for the source code in case the vendor goes out of business.
In other cases they might want to audit only certain parts of the OS, or just to integrate their own code at a level that out of the box Windows interoperability doesn't support.
If you say have a hardware encryption & security module which connects directly to the hard hard drive and includes a smart card reader for access you will probably need the ability to run custom code in the BIOS, boot loader and OS levels.
Then again if you have the resources of a US, major European power, Russian or Chinese state agency you might have the ability to also audit the full source code.
It comes in really handy for figuring out specific bugs or implementation details. I'd imagine any large-enough customer would find similar value.
http://arstechnica.com/security/2013/06/nsa-gets-early-acces...
Oh btw, Apple and Intel do this, too, now (Intel may have been doing it for years, but we know for a fact Apple "volunteered" to do it, too, this year at Obama's Cyber Summit). As far as we know Google has refused to do it, and hopefully it stays that way.
Large banks for example will get information about new "zero-day" vulnerabilities from their TAM some times months before a patch is released so they could adjust accordingly.
The NSA doesn't get an exploit they are notified about the vulnerability in good faith, in some cases Microsoft and their partners will release a signature which can enabled host or network bases intrusion detection/prevention systems to mitigate the vulnerability until it's patched.
There are other initiatives by various security vendors the most prominent would be ZDI by TippingPoint (now HP) which actually buy exploits so they could make signatures for their IPS, they notify their partners but in many cases withhold the vulnerability information for upto 6 months from the vendor of the vulnerable product.
Source?
If you have to patch 10,000 machines you don't want to be in a position to hear about it with everyone else on patch Tuesday.
If you a big enough client you'll know it's coming and even might get the update ahead of time.
Super highly unlikely. They worked closely together. Viz http://www.huffingtonpost.com/2014/05/06/nsa-google_n_527343...