Or they did it out of moral reasons, which is not something every discoverer of vulnerabilities will care about
In either case only paying $40,000 for disclosing an exploit like this sends a clear message from Microsoft. They don't take their user's security seriously. And it also incentivizes certain outcomes -- They're cheap and less moral actors who are only motivated by the finanical reward won't bother to engage with Microsoft.
Use Microsoft products at your own peril.
Put another way: just because the researchers didn't (publicly) complain doesn't put MSFT in the right here. There are more than a few kernel developers who didn't raise hell about Linus' abusive behavior. Yet even Linus himself realized his behavior had to change.