I keep saying there's more to it, and you keep pointing to it as some sort of meaningful metric. There's a whole hell of a lot more to security than just having identified flaws - like how quick you fix them, how much time you put into finding them yourself, whether or not you support others finding them and reward them for their effort, how open and honest you are about those issues.
Microsoft is leading the pack in every regard on those issues, and other companies are modeling themselves after microsoft.
You criticize them for their Patch Tuesday model, which has been around for a long, long time, yet other companies are following it because it's a great model.
You want to count the number of bugs? Well Apple has significantly less bugs, yet their model consists of lying about their security to everyone else and denying the existence of bugs when they are reported. When they're put out in public and an apple customer contacts apple, apple's customer reps are INSTRUCTED TO DENY THE EXISTENCE OF THE ISSUE. So yes, Apple has less vulnerability counts - but how could they possible be a better product in terms of security? That's a joke, and anyone worth a crap in security recognizes that.
If you want to know how well microsoft is doing then I suggest you follow InfoSec mailing lists and the blogs/journals that considered to have some of the top authors in the field.
And your still ignoring the fact that microsoft has a market share, over a period of time, that no one else in the industry can rival. MS has been the biggest target of everyone for the last two decades - we're surprised a lot of problems are found? We're going to use that to declare them terrible when it comes to security?
MS is suffering mostly form a reputation from the past. They're not perfect, but they're further ahead of most of the other big tech companies.
And I do work in .Net - used to do a lot more, but I still find myself working in it from time to time and I certainly keep up on the platform due to my role.