I don't know Exim to tell you how to do it there, but this would be fairly trivial with Postfix. Run the mail through SA, and if the X-Spam-Status header says it is spam, rewrite the destination mailbox. Exchange should handle it from there.
However: do you REALLY want a common spam mailbox for everyone in the company? This has a real chance of exposing spersonal or company confidential stuff to recipients that shouldn't have it. Loren