Chrome has a superior "PepperFlash" sandbox (Google strong-armed Adobe into supporting it) that has prevented the recent 0-days from breaking out of the browser process. Worst case is a temporary infection of a padded cell with no access to anything. An occasional browser restart will vanish any that might get so far.

Flash is integrated into IE 10 and IE 11 (where M$'s lame sandbox has prevented nothing). Search on "group policy disable flash" for a procedure that absolutely prevents Flash from running in IE. I prefer simply setting "Deny all add-ons unless specifically allowed. . ."

