I'm sure it's the case that its trivially easy to set up an internet facing server that runs Linux and run some web service and then never patch it, that is the problem, and giving inflated scores for Linux attacks.

You can rent a low end server for just a few dollars a month (see lowendbox blog).

If you want to get a Windows server and connect it publicly to the internet you'd have to put in a lot of effort, enough perhaps to deter anyone who doesn't know what they're doing.

