That's an entirely different attack scenario. To succeed at that attack, my computer would already need to be running malware. At that point, they've already won.
Or you visit a webpage that makes a request to an arbitrary server on an arbitrary port while not running a default-deny application firewall
Or you visit a webpage that makes a request to an arbitrary server on an arbitrary port while not running a default-deny application firewall