Certainly, under the correct conditions.
If your Windows OS is left in 'stock' configurations, chances are you've got all kinds of stuff enabled (to give you that 'rich Internet experience') which would include 'active scripting'; Adobe Flash' and who knows what else.
These items have far reaching, powerful functions, which the bad guys know most Windows users are unaware of, and promptly take advantage of.
As some above answers imply, never open unknown mail; and in reality, all mail should be opened in a "sandbox" in order to deflect malware sent by your friends compromised system.
"Sandboxie" has this capacity, but I think it's confined to browsers, or perhaps on a limited time offer kind of thing.
(With Linux, you don't have nearly the Windows paranoia from these unknowns)