I think even without metadata server replacement this attack would still be painful. The ability to reconfigure network on a victim sounds painful
There might be a persistence issue, it seems like part of this attack was that the IP was persisted to /etc/hosts even after the real DHCP server took over again. But even just writing to /etc/hosts could open the door redirecting traffic to an attacker controlled server.