Security researchers do the work and MS wants the information for free. If MS really wants to fix the problem, let them pay. I don't see the problem with this.
It's an exaggerated example, but it seems to me that sometimes what is in the best interest of everyone as a whole outweighs the desire of some individuals to exploit the weaknesses of others for personal gain.
I'm not a particularly big fan of firms that sell vulnerabilities (full disclosure: I've never sold any vulnerabilities I've discovered), but I would be incredibly uncomfortable with the idea that there should be a litmus test for what information is safe to trade, and what isn't.