> Not OSS != no source access.
Furthermore, no source access != no way to fix problems.
People have been fixing things with no source for ages, EULAs be damned. If the fix is literally flipping a single bit, the decision is easy. Just do it. The vendor doesn't need to know nor care what we did to fix it, but often giving a detailed description to them of the problem --- one that comes out of the process of fixing it --- will help them fix it quickly and distribute to their other customers too. I've had this experience a few times.
Obviously, "the byte at 0x73F441 of somefile.dll should be 31, not 32" is not how you should communicate such things to the vendor, but they do appreciate your effort in debugging the issue instead of immediately blaming it on a fault in their software. ;-)
(And relatedly, no source access != no way to find problems either, as the security community shows quite plainly...)