I haven't had time to look properly at this, and the articles I've skimmed so far have been lacking, but...
1) SMM attacks are at least a decade old, and complicated to pull off - you need to write very specific code.
2) This exploit still needs ring0 access to pull off, right?