I think that when "Microsoft doesn’t ask and can’t be told how the government uses such tip-offs" the problems begin. I'd really like to believe what we're told - that the exploits/vulnerabilities were only used for software sold to foreign governments - but I'd be hard pressed to actually believe that foregoing any concrete proof. Again, unless someone explicitly says "no", they seem hell-bent on using anything they can for their own increased surveillance; domestic or otherwise.
Lastly, regarding MAPP, I think this is something entirely different they're hinting at. I see several things on the MAPP criteria [1] I doubt any intelligence agencies align with (Are you willing to have your company name and URL displayed on our MAPP website?, Do you provide active protection technology for Microsoft products and is your product commercially available?, and Do you sell or create products used to attack or weaken the security posture of networks or applications? are my favourites).
[1] http://www.microsoft.com/security/msrc/collaboration/mapp/cr...
Security researchers are in high demand right now and with good reason - a competent security researcher can write an exploit given a limited amount of information, and I find it unlikely MS themselves necessarily has exploit code for all situations.
A competent security researcher should be able to go from this diff: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.g... to full exploit code in a day. An afternoon, even.
I bring this up because there's nothing particularly magical about writing exploits, even if it isn't a skill a ordinary programmer possess. If the vulnerability has already been found, so whether or not this is simply MAPP/CIPP or something more nefarious, your distinction seems a bit academic.