Good luck trying that once that memory is encrypted with SGX.
The alternative to hooking into UEFI code would be to just write to flash by yourself. SMM has additional permissions there.