No. None of this is accurate.
Microsoft gets information about vulnerabilities from the same sources as everyone else. They outspend every other software vendor by something like 4:1 on outside software security consultants. If they are in a privileged position regarding WinAPI software vulnerabilities at all, it is a marginally privileged position. No security person working at Microsoft would tell you they were confident that outsiders weren't holding severe, exploitable vulnerabilities back.
NSA, meanwhile, is as competent at sourcing vulnerabilities as any organization on the planet. They have internal research teams that generate them that are presumably competitive with any private research team, and they apparently purchase vulnerabilities like everyone else --- not from Microsoft, but from research teams that sell vulnerabilities.
Microsoft gives pre-release information about vulnerabilities to lots of different organizations; for instance, the IDS and network security vendors get pre-release info to create signatures. This program is, IIRC, over a decade old.
NSA is a dual-role organization; it also houses the USG's center for defensive technology expertise. It is the opposite of surprising that NSA would have the same relationship with Microsoft as, say, Symantec would.
Finally, CISPA does nothing resembling what you claimed it does. CISPA is opt-in; it cannot be used to force a company to disclose anything. CISPA is about incident data, not vulnerabilities. It is already lawful to share vulnerability information with the government. The gray area in data sharing is non- anonymized incident data, which can be covered by any of 10+ different regulations that make even IP-level metadata risky to share for collaborative defense.
CISPA is an extraordinarily short bill; you can simply read it instead of taking my word for it.