The Windows 0-day is CVE-2015-2360 from MS15-061, it appears to be the only one Microsoft admits to have been exploited or used to attack it's customers.
This is true for every single piece of software ever written. Msft is no different in this regard.
Then there's also Coq and such.
Of course, usually the amount of vulnerabilities exponentially correlates to the size of the codebase.