1. (quite obviously)- make sure that non-administrative account is used for daily tasks
2. install all required updates (and set up AV for updating itself)
3. install EMET 3 - its a freeware, you can call it a "DEP on steroids"- its usefull to protect against so-called "0 day exploits"
4. if possible - run those applications within sandbox - there is a great program called "sandboxie" (no, i do not advert for it)- free for most uses, you can buy a license (which is cheap), easy to use.