Big outfits like Microsoft are authorized to issue their own CVE numbers and have a range allocated to them

Presumably a large range, because no one wants to see articles on the Reg, Slashdot, etc. about how Microsoft had so many CVEs one year they used up their entire range and had to request a another.

