I'm speaking from the point of view of Microsoft as a user of open source software. Microsoft is not the end-user, but they are taking open source code and using it within their own product, Windows.
Microsoft has the freedom to modify the OSS components in Windows to patch security vulnerabilities.
I don't see that mentioned in The Four Freedoms of Open Source: https://yairudi.com/foss-principles-explained-ch-ii-open-sou...