Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected. This release contains six new rules two of which are shared object rules, as well as two modified rules. The release provides protection against a vulnerability in Windows win32k that attackers have exploited in the wild. This rule fires when the AZORult trojan attempts to make an outbound connection to its command and control server. The escalation of privilege bug was identified as CVE20191132.”]
Source: https://blog.snort.org/2019/07/snort-rule-update-for-july-23-2019.html