"If there is a bug somewhere and if it stays unpatched..." and if someone could somehow rewrite firmware from unpriviledged user application, and if, after all that, someone could somehow "call home" (critical for any exploit to be useful, and has to be executed, again, using the unpriviledged user level, which will be intercepted by even primitive firewalls) ...
I'd say the chances for exploiting this in an undetecteble rootkit are pretty "remote". Not that vigilance is not warranted, but releasing the exploits will help others, besides Intel, to find a rootkit detection and/or fix on a callback level.
Well done, Joanna!