What's the basis for your assertion?
At the level of systems we're discussing, a Windows installation would be operated by experienced Windows administrator. Thus the appropriate comparison group for Linux would be something like a university-run supercomputing cluster. We don't often hear of these being taken over for ransom.
I don't have any basis, just what I expect. Windows has been fuzzed and reverse engineered to the moon and back. Desktop Linux? I doubt it.
I'd agree that yes, distros meant for desktop usage have less secure defaults, but that's not necessarily to say they're "less secure" if you understand how you're using them.
I trust nginx, sshd, postgres, postfix, etc. much more than I trust the gnome file manager, evince, dbus, pulse.
For every exploit that nginx currently has, there probably are a thousand lurking in gnome's file roller.
Unless your entirely hypothetical scenario involves privilege escalation vulnerabilities, which I'll admit aren't unheard of in Linux but are fairly rare and usually patched within hours when they are discovered.