because these characters have special meaning to windows OS. Which means windows might think these characters are a directive to it to do special processing instead of just a character.
If you look at an example like sql injection (sort of the same type of concept), you can see how this type of accidental (or even malicious) processing can be dangerous.